Description
DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.
Remediation
References
Related Vulnerabilities
WordPress Plugin jQuery Mega Menu Widget 'skin' Parameter Local File Include (1.0)
MySQL CVE-2013-1506 Vulnerability (CVE-2013-1506)
SugarCRM Improper Restriction of XML External Entity Reference Vulnerability (CVE-2014-3244)
Oracle Application Server Other Vulnerability (CVE-2002-1631)
WordPress Plugin aoringo TAG upper Cross-Site Scripting (0.1.6)