marked project records
11 published records for vendor marked project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-1333 Inefficient Regular Expression Complexity2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2026-41680No exploit | Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizermarked project · marked · CWE-400 | High8.7 | — | 0.5% | Apr 24, 2026 |
31Monitor | CVE-2015-8854No exploit | The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trimarked project · marked · CWE-1333 | High7.5 | — | 4.3% | Jan 23, 2017 |
31Monitor | CVE-2022-21680No exploit | Cubic catastrophic backtracking (ReDoS) in markedmarked project · marked · CWE-400 | High7.5 | — | 2.9% | Jan 14, 2022 |
31Monitor | CVE-2022-21681No exploit | Exponential catastrophic backtracking (ReDoS) in markedmarked project · marked · CWE-400 | High7.5 | — | 2.8% | Jan 14, 2022 |
31Monitor | CVE-2021-21306No exploit | Denial of Service in Markedmarked project · marked · CWE-400 | High7.5 | — | 2.5% | Feb 8, 2021 |
31Monitor | CVE-2017-16114No exploit | The marked module is vulnerable to a regular expression denial of service.marked project · marked · CWE-400 | High7.5 | — | 1.8% | Jun 6, 2018 |
27Monitor | CVE-2018-25110No exploit | Regular Expression Denial of Service (ReDoS) in markedjs/markedmarked project · marked · CWE-1333 | Medium6.9 | — | 0.6% | May 23, 2025 |
25Monitor | CVE-2014-3743No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrarymarked project · marked · CWE-79 | Medium6.1 | — | 1.7% | Jan 6, 2020 |
24Monitor | CVE-2017-1000427No exploit | marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.marked project · marked · CWE-79 | Medium6.1 | — | 1.5% | Jan 2, 2018 |
24Monitor | CVE-2016-10531No exploit | marked is an application that is meant to parse and compile markdown.marked project · marked · CWE-79 | Medium6.1 | — | 1.5% | May 31, 2018 |
18Monitor | CVE-2015-1370No exploit | Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attmarked project · marked | Medium4.3 | — | 2.1% | Jan 27, 2015 |
- CVE-2026-4168034Monitor
Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizer
HighCVSS 8.7No exploitEPSS 1%marked project · markedApr 24, 2026
- CVE-2015-885431Monitor
The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that tri
HighCVSS 7.5No exploitEPSS 4%marked project · markedJan 23, 2017
- CVE-2022-2168031Monitor
Cubic catastrophic backtracking (ReDoS) in marked
HighCVSS 7.5No exploitEPSS 3%marked project · markedJan 14, 2022
- CVE-2022-2168131Monitor
Exponential catastrophic backtracking (ReDoS) in marked
HighCVSS 7.5No exploitEPSS 3%marked project · markedJan 14, 2022
- CVE-2021-2130631Monitor
Denial of Service in Marked
HighCVSS 7.5No exploitEPSS 2%marked project · markedFeb 8, 2021
- CVE-2017-1611431Monitor
The marked module is vulnerable to a regular expression denial of service.
HighCVSS 7.5No exploitEPSS 2%marked project · markedJun 6, 2018
- CVE-2018-2511027Monitor
Regular Expression Denial of Service (ReDoS) in markedjs/marked
MediumCVSS 6.9No exploitEPSS 1%marked project · markedMay 23, 2025
- CVE-2014-374325Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary
MediumCVSS 6.1No exploitEPSS 2%marked project · markedJan 6, 2020
- CVE-2017-100042724Monitor
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
MediumCVSS 6.1No exploitEPSS 2%marked project · markedJan 2, 2018
- CVE-2016-1053124Monitor
marked is an application that is meant to parse and compile markdown.
MediumCVSS 6.1No exploitEPSS 1%marked project · markedMay 31, 2018
- CVE-2015-137018Monitor
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) att
MediumCVSS 4.3No exploitEPSS 2%marked project · markedJan 27, 2015