« Volver al listado

Markdown-it Project

Markdown-it Project Markdown-it: vulnerabilidades y CVE

Markdown-it Project Markdown-it tiene 6 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses2
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-48988Media (5.3)0.43%—17 jun 2026
markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from…
CVE-2026-2327Media (5.5)0.68%—12 feb 2026
Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long…
CVE-2025-7969Media (6.9)0.24%—21 ago 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files…
CVE-2015-10005Alta (7.5)0.95%—27 dic 2022
A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation leads to inefficient regular expression…
CVE-2022-21670Media (5.3)2.2%—10 ene 2022
markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a…
CVE-2015-3295Media (5.3)1.3%—7 jun 2017
markdown-it before 4.1.0 does not block data: URLs.