{"id":82449,"date":"2026-07-23T16:46:24","date_gmt":"2026-07-23T13:16:24","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-65914-dompurify-before-3-3-2-mutation-xss-via-re-contextualization\/"},"modified":"2026-07-23T16:46:24","modified_gmt":"2026-07-23T13:16:24","slug":"cve-2026-65914-dompurify-before-3-3-2-mutation-xss-via-re-contextualization","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-65914-dompurify-before-3-3-2-mutation-xss-via-re-contextualization\/","title":{"rendered":"CVE-2026-65914 &#8211; DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization"},"content":{"rendered":"<p>CVE ID :CVE-2026-65914<\/p>\n<p>  Published : July 23, 2026, 1:16 p.m. | 31\u00a0minutes ago<\/p>\n<p>  Description :DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.<\/p>\n<p>  Severity: 5.3 | MEDIUM<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-65914 Published : July 23, 2026, 1:16 p.m. | 31\u00a0minutes ago Description :DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-82449","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/82449","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=82449"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/82449\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=82449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=82449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=82449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}