CVE-2026-75838

DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.


We have discovered 63,594 live websites that are affected by CVE-2026-75838.

Run a Free Instant Scan




Affected Software

Product  DOMPurify
Category JavaScript Libraries
Vulnerable Domains63,594 live websites (100% of DOMPurify install base)
Vulnerable Versions
  • from 0 through 3.4.13
Vulnerable Versions Count72 versions ( 100% of all versions)



Details

  • Published - Aug 18, 2026
  • Updated - Aug 18, 2026

Credits

  • koyokr (reporter)

Website Distribution by Country

Number of websites using CVE-2026-75838
United States17,245 websites



Germany8,754 websites
France3,863 websites
Japan3,044 websites
GB2,541 websites
Netherlands2,494 websites
Brazil2,099 websites
Italy2,006 websites
Poland1,957 websites
Switzerland1,584 websites

Website Distribution by TLD

Number of websites using CVE-2026-75838
.com23,897 websites
.de6,126 websites
.org2,908 websites
.nl2,237 websites
.com.br1,960 websites
.fr1,781 websites
.co.uk1,502 websites
.pl1,472 websites
.it1,460 websites
.net1,426 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-75838

Top websites that are affected by CVE-2026-75838. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.*****.com United States*,***
*****.*********.com United States*,***
********.org United States*,***
*******.com United States*,***
***********.ch Switzerland*,***
*****.com United States*,***
********.org United States*,***
***********.dk Denmark*,***
************.org France*,***
*********.com United States*,***
See full domain list

FAQ

A total of 63,594 websites have been identified as vulnerable to CVE-2026-75838, based on global website indexing conducted by WebTechSurvey.
The DOMPurify is affected by the CVE-2026-75838 vulnerability.
DOMPurify versions up to 3.4.13 are vulnerable to CVE-2026-75838.
CVE-2026-75838 is resolved in version 3.4.13 of DOMPurify.