HackMD / CodiMD
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-46655 | CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain c… | MEDIUM | 4.9 | Apr 26, 2025 |
| CVE-2025-46654 | CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file tha… | MEDIUM | 4.9 | Apr 26, 2025 |
| CVE-2024-38353 | CodiMD - Missing Image Access Controls and Unauthorized Image Access | MEDIUM | 5.3 | Jul 10, 2024 |
| CVE-2024-38354 | Cross-site Scripting in Hackmd.io Notes lead by HTML Injection | HIGH | 8.1 | Jul 10, 2024 |
| CVE-2024-22778 | HackMD CodiMD <2.5.2 is vulnerable to Denial of Service. | HIGH | 7.5 | Feb 21, 2024 |
| CVE-2019-15499 | CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL. | MEDIUM | 6.1 | Aug 23, 2019 |
Showing 1 to 5 of 5 CVEs