Xmldom Project maintains a lightweight XML document-object-model library widely embedded in Node.js applications and server-side JavaScript environments, where its compact footprint belies significant downstream exposure. The recurring vulnerability signal centers on XML parsing and object-handling weaknesses—improper encoding and escaping, input validation gaps, prototype pollution, and interpretation conflicts—that reflect the challenges of parsing untrusted markup and managing dynamic object properties in permissive JavaScript contexts. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xmldom Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39353CRITICAL xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses XML that is not well-formed because it contains multiple | Nov 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-37616CRITICAL A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the | Oct 11, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-32796MEDIUM xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape speci | Jul 27, 2021 | 5.3 | 19 | NO | NO |
CVE-2021-21366MEDIUM xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.4.0 and older do not correctly preserve system identifie | Mar 12, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xmldom Project.
Media articles that mention a CVE ID that affects a product developed by Xmldom Project — matched by CVE ID, not by vendor name.