CVE Browser
CVE-2025-46655 MEDIUM
CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain c…
CVSS 4.9 EPSS 0.25% Apr 26, 2025
CVE-2025-46654 MEDIUM
CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file tha…
CVSS 4.9 EPSS 0.26% Apr 26, 2025
CVE-2024-38353 MEDIUM
CodiMD - Missing Image Access Controls and Unauthorized Image Access
CVSS 5.3 EPSS 1.15% Jul 10, 2024
CVE-2024-38354 HIGH
Cross-site Scripting in Hackmd.io Notes lead by HTML Injection
CVSS 8.1 EPSS 0.42% Jul 10, 2024
CVE-2024-22778 HIGH
HackMD CodiMD <2.5.2 is vulnerable to Denial of Service.
CVSS 7.5 EPSS 0.69% Feb 21, 2024
CVE-2019-15499 MEDIUM
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.
CVSS 6.1 EPSS 0.86% Aug 23, 2019
Showing 1 to 6 CVEs · page 1