Mermaid Project
Mermaid Project Mermaid: vulnerabilidades y CVE
Mermaid Project Mermaid tiene 6 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-41159 | Media (5.3) | 0.55% | — | 29 may 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows injecting CSS that applies outside of the… |
| CVE-2026-41150 | Media (5.3) | 0.53% | — | 29 may 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the… |
| CVE-2025-54880 | Media (5.1) | 0.38% | — | 19 ago 2025 | Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 11.9.0 and earlier,… |
| CVE-2022-31108 | Media (6.1) | 0.91% | — | 28 jun 2022 | Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. An attacker is able to inject arbitrary `CSS` into the… |
| CVE-2021-43861 | Media (5.4) | 0.91% | — | 30 dic 2021 | Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run… |
| CVE-2021-35513 | Media (6.1) | 1.0% | — | 27 jun 2021 | Mermaid before 8.11.0 allows XSS when the antiscript feature is used. |