DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode() function returns false for foreign-realm nodes, causing DOMPurify to stringify the element (yielding '[object HTMLDivElement]'), silently reset IN_PLACE to false, and return the unsanitized element unchanged with any XSS payloads intact.
We have discovered 63,648 live websites that are affected by CVE-2026-65904.
| Product | |
| Category | JavaScript Libraries |
| Vulnerable Domains | 63,648 live websites (100% of DOMPurify install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 66 versions ( 93% of all versions) |
| 17,529 websites | |
| 8,640 websites | |
| 3,898 websites | |
| 2,889 websites | |
| 2,597 websites | |
| 2,443 websites | |
| 2,181 websites | |
| 1,993 websites | |
| 1,841 websites | |
| 1,558 websites |
| .com | 24,248 websites |
| .de | 6,008 websites |
| .org | 2,873 websites |
| .nl | 2,193 websites |
| .com.br | 2,025 websites |
| .fr | 1,808 websites |
| .co.uk | 1,533 websites |
| .it | 1,453 websites |
| .net | 1,417 websites |
| .pl | 1,397 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.*****.com | *,*** | ||
| *****.*********.com | *,*** | ||
| ********.org | *,*** | ||
| ***********.ch | *,*** | ||
| *****.com | *,*** | ||
| ********.org | *,*** | ||
| ***********.dk | *,*** | ||
| ************.org | *,*** | ||
| *********.com | *,*** | ||
| *************.com | *,*** |
FAQ