Looking for the vulnerability index of Invicti's legacy products?
DOMPurify Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2025-26791 - Vulnerability Database

DOMPurify Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2025-26791

Medium
Reference: CVE-2025-26791
Title: DOMPurify Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

DOMPurify before 3.2.4 has an incorrect template literal regular expression sometimes leading to mutation cross-site scripting (mXSS).