CVE-2026-83607 | xmldom prior 0.8.14/0.9.11 DOMParser/XMLSerializer cross site scripting
A vulnerability marked as problematic has been reported in xmldom. Affected by this issue is the function Document.createElement/XMLSerializer.serializeToString of the component DOMParser/XMLSerializer. Performing a manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-83607. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More