CVE-2024-47875(cure53 / dompurify)

LOWCVSS 6.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dompurify

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Affected systems

Vendors
Products
dompurify

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-26: 209-26
Referenced assets1 URL
By indicator
Full discourse2 posts
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2024-47875 [CRITICAL/PoC] CVE-2024-47875 🔗 https://exploitgrid.net/exploits/436abfa3-c903-4a7d-b3c7-4dbbd77bbfa3

    1000027
    66 followersView on X
  • ExploitGrid@exploitgrid

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2024-47875 CVE-2026-12227 CVE-2026-12227 CVE-2026-15015 CVE-2026-62878 ..🧵👇

    1000050
    66 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcure53dompurify---

Explore more