Hackmd
Hackmd Codimd: vulnerabilidades y CVE
Hackmd Codimd tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-46655 | Media (4.9) | 0.25% | — | 26 abr 2025 | CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE:… |
| CVE-2025-46654 | Media (4.9) | 0.26% | — | 26 abr 2025 | CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file. |
| CVE-2024-38354 | Media (6.1) | 0.42% | — | 10 jul 2024 | CodiMD allows realtime collaborative markdown notes on all platforms. The notebook feature of Hackmd.io permits the rendering of iframe `HTML` tags with an improperly sanitized `name` attribute. This vulnerability… |
| CVE-2024-38353 | Media (5.3) | 1.1% | — | 10 jul 2024 | CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and access control vulnerability allowing an unauthenticated attacker to gain unauthorised access to… |
| CVE-2024-22778 | Alta (7.5) | 0.69% | — | 21 feb 2024 | HackMD CodiMD <2.5.2 is vulnerable to Denial of Service. |
| CVE-2019-15499 | Media (6.1) | 0.86% | — | 23 ago 2019 | CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL. |