DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
We have discovered 63,663 live websites that are affected by CVE-2026-66010.
| Product | |
| Category | JavaScript Libraries |
| Vulnerable Domains | 63,663 live websites (100% of DOMPurify install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 71 versions ( 100% of all versions) |
| 17,537 websites | |
| 8,640 websites | |
| 3,898 websites | |
| 2,889 websites | |
| 2,598 websites | |
| 2,443 websites | |
| 2,181 websites | |
| 1,994 websites | |
| 1,841 websites | |
| 1,558 websites |
| .com | 24,260 websites |
| .de | 6,008 websites |
| .org | 2,874 websites |
| .nl | 2,193 websites |
| .com.br | 2,025 websites |
| .fr | 1,808 websites |
| .co.uk | 1,533 websites |
| .it | 1,454 websites |
| .net | 1,417 websites |
| .pl | 1,397 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.*****.com | *,*** | ||
| *****.*********.com | *,*** | ||
| ********.org | *,*** | ||
| ***********.ch | *,*** | ||
| *****.com | *,*** | ||
| ********.org | *,*** | ||
| ***********.dk | *,*** | ||
| ************.org | *,*** | ||
| *********.com | *,*** | ||
| *************.com | *,*** |
FAQ