Marked Project / Marked
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41680 | Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizer | HIGH | 8.7 | Apr 24, 2026 |
| CVE-2018-25110 | Regular Expression Denial of Service (ReDoS) in markedjs/marked | MEDIUM | 6.9 | May 23, 2025 |
| CVE-2022-21681 | Exponential catastrophic backtracking (ReDoS) in marked | HIGH | 7.5 | Jan 14, 2022 |
| CVE-2022-21680 | Cubic catastrophic backtracking (ReDoS) in marked | HIGH | 7.5 | Jan 14, 2022 |
| CVE-2021-21306 | Denial of Service in Marked | HIGH | 7.5 | Feb 8, 2021 |
| CVE-2014-3743 | Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML… | MEDIUM | 6.1 | Jan 6, 2020 |
| CVE-2017-16114 | The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characters can block for… | HIGH | 7.5 | Jun 7, 2018 |
| CVE-2016-10531 | marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parses input, specifically HTML entities, it… | MEDIUM | 6.1 | May 31, 2018 |
| CVE-2017-1000427 | marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser. | MEDIUM | 6.1 | Jan 2, 2018 |
| CVE-2015-8854 | The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophi… | HIGH | 7.5 | Jan 23, 2017 |
| CVE-2015-1370 | Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript… | MEDIUM | 4.3 | Jan 27, 2015 |
Showing 1 to 11 of 11 CVEs