https://retout.co.uk/2024/01/01/trusted-types/
Prevent DOM-XSS with Trusted Types - a smarter DevSecOps approach | Tim Retout
Jan 1, 2024 - It can be incredibly easy for a frontend developer to accidentally write a client-side cross-site-scripting (DOM-XSS) security issue, and yet these are hard...
dom xsstrusted types
https://sboxr.com/
Sboxr | Scanner for DOM XSS and Client-side Security
dom xssclient sidescannersecurity
https://vuxml.freebsd.org/freebsd/f8b7af82-2116-11f0-8ca6-6c3be5272acd.html
VuXML: Grafana -- DOM XSS vulnerability
dom xssvuxmlgrafanavulnerability
https://advisories.gitlab.com/npm/open-webui/CVE-2025-64495/
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled...
CVE-2025-64495 Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE: The functionality that...
https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2026-34716/
AVideo: DOM XSS via Unsanitized Display Name in WebSocket Call Notification | GitLab Advisory...
CVE-2026-34716 AVideo: DOM XSS via Unsanitized Display Name in WebSocket Call Notification: The AVideo YPTSocket plugin's caller feature renders incoming call...
https://advisories.gitlab.com/npm/@pagefind/modular-ui/CVE-2024-45389/
DOM clobbering could escalate to Cross-site Scripting (XSS) | GitLab Advisory Database (GLAD)
CVE-2024-45389 DOM clobbering could escalate to Cross-site Scripting (XSS): Pagefind initializes its dynamic JavaScript and WebAssembly files relative to the...
cross site scripting
https://advisories.gitlab.com/npm/rollup/CVE-2024-47068/
DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS | GitLab Advisory Database...
CVE-2024-47068 DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS: We discovered a DOM Clobbering vulnerability in rollup when bundling...
https://advisories.gitlab.com/composer/craftcms/commerce/CVE-2026-25482/
Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard...
CVE-2026-25482 Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget): A stored DOM XSS vulnerability exists in...
https://advisories.gitlab.com/golang/gogs.io/gogs/CVE-2026-26276/
Gogs: DOM-based XSS via milestone selection | GitLab Advisory Database (GLAD)
CVE-2026-26276 Gogs: DOM-based XSS via milestone selection: It was confirmed in a test environment that an attacker can store an HTML/JavaScript payload in a...
dom based xssgogsvia
https://developer.chrome.com/docs/lighthouse/best-practices/trusted-types-xss
Mitigate DOM-based XSS with Trusted Types | Lighthouse | Chrome for Developers
Learn more about mitigating DOM-based XSS with Trusted Types
dom based xsstrusted typesmitigate
https://advisories.gitlab.com/npm/locize/GHSA-w937-fg2h-xhq2/
locize Client SDK: Cross-origin DOM XSS & Handler Hijack Through Missing e.origin Validation in...
https://advisories.gitlab.com/composer/yeswiki/yeswiki/CVE-2025-24017/
Unauthenticated DOM Based XSS in YesWiki | GitLab Advisory Database (GLAD)
CVE-2025-24017 Unauthenticated DOM Based XSS in YesWiki: It is possible for any end-user to craft a DOM based XSS on all of YesWiki's pages which will be...
dom based xssyeswikigitlabadvisorydatabase
https://advisories.gitlab.com/npm/telejson/GHSA-ccgf-5rwj-j3hv/
TeleJSON: DOM XSS via unsanitised constructor name in `new Function()` | GitLab Advisory Database...
GHSA-ccgf-5rwj-j3hv TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`: telejson versions prior to 6.0.0 (released 2022) are vulnerable to...
https://advisories.gitlab.com/npm/clevertap-web-sdk/CVE-2026-26861/
CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent...
CVE-2026-26861 CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function: CleverTap Web SDK version 1.15.2 and...
dom based xssweb sdkclevertapvulnerablevia
https://advisories.gitlab.com/npm/astro/CVE-2024-47885/
DOM Clobbering Gadget found in astro's client-side router that leads to XSS | GitLab Advisory...
CVE-2024-47885 DOM Clobbering Gadget found in astro's client-side router that leads to XSS: A DOM Clobbering gadget has been discoverd in Astro's client-side...
https://advisories.gitlab.com/npm/directus/GHSA-9qrm-48qf-r2rw/
Directus has a DOM-Based cross-site scripting (XSS) via layout_options | GitLab Advisory Database...
GHSA-9qrm-48qf-r2rw Directus has a DOM-Based cross-site scripting (XSS) via layout_options: Directus allows an authenticated attacker to save cross site...
https://advisories.gitlab.com/npm/petite-vue-i18n/CVE-2025-53892/
vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes | GitLab...
CVE-2025-53892 vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes: The escapeParameterHtml: true option in Vue I18n is...
https://advisories.gitlab.com/pypi/open-webui/CVE-2025-64495/
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled...
CVE-2025-64495 Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE: The functionality that...
https://advisories.gitlab.com/npm/i18nextify/GHSA-6457-mxpq-4fqq/
i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes | GitLab...
GHSA-6457-mxpq-4fqq i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes: Versions of i18nextify prior to 4.0.8...