xmldom

npmv0.6.0

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

License MITpermissive36 versions2 maintainers0 deps1,514,456 weekly dl
git://github.com/xmldom/xmldom
37
/ 100
Health
do not use

xmldom has critical vulnerabilities — do not use

Update to >= 0.9.10 to fix known vulnerabilities

  • Low health score (37/100)
  • 5 high severity vulnerabilities
  • 1 critical vulnerabilities
Health breakdown0 – 100
0/25
maintenance
17/20
popularity
0/25
security
15/15
maturity
5/15
community
Vulnerabilities
7
1 critical5 high1 medium
Advisories (7)
SeverityIDSummaryFixed in
highCVE-2026-41673xmldom: Uncontrolled recursion in XML serialization leads to DoS0.9.10
mediumCVE-2021-32796Misinterpretation of malicious XML input0.7.0
criticalCVE-2022-39353xmldom allows multiple root nodes in a DOM0.9.0-beta.4
highCVE-2026-41674xmldom has XML injection through unvalidated DocumentType serialization0.9.10
highCVE-2026-41672xmldom has XML node injection through unvalidated comment serialization0.9.10
highCVE-2026-34601xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion0.9.9
highCVE-2026-41675xmldom has XML node injection through unvalidated processing instruction serialization0.9.10

Bundle & TypeScript

🌟

TypeScript

7/10typed
Types from @types/xmldom (DefinitelyTyped)
Quality signals
Publish security
npm signed

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/npm/xmldom

First published · 2012-01-06T09:49:36.833Z

Last updated · 2021-04-17T16:41:51.033Z

xmldom — Health Score 37/100 | DepScope