CVE-2021-32796 affects xmldom versions 0.6.0 and older, a JavaScript XML DOM parser and serializer. The vulnerability stems from improper escaping of special characters when serializing XML elements removed from their parent, potentially causing unexpected syntactic changes in downstream applications. With a CVSS score of 5.3 (Medium), this issue is network-exploitable with low attack complexity, requiring no user interaction or privileges, and primarily impacts integrity (I:L). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.7.0CPE matchmatch criteria | cpe:2.3:a:xmldom_project:xmldom:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.