CVE-2026-83610 | xmldom up to 0.6.0/0.8.14/0.9.11 EntityReference Document.createEntityReference Name xml injection

SecurityVulns

A vulnerability was found in xmldom up to 0.6.0/0.8.14/0.9.11. It has been classified as critical. The affected element is the function Document.createEntityReference of the component EntityReference Handler. Performing a manipulation of the argument Name results in xml injection.

This vulnerability is cataloged as CVE-2026-83610. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More