Skip to content
Noroxi

HackMD records

5 published records for vendor hackmd.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
60%
Median publish → KEV
No record has entered KEV

All records

5 records
  • HackMD CodiMD <2.5.2 is vulnerable to Denial of Service.

    HighCVSS 7.5No exploitEPSS 1%

    hackmd · codimdFeb 21, 2024

  • CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with

    MediumCVSS 6.1No exploitEPSS 1%

    hackmd · codimdAug 23, 2019

  • Cross-site Scripting in Hackmd.io Notes lead by HTML Injection

    MediumCVSS 6.1No exploitEPSS 0%

    hackmd · codimdJul 10, 2024

  • CodiMD - Missing Image Access Controls and Unauthorized Image Access

    MediumCVSS 5.3Proof of conceptEPSS 1%

    hackmd · codimdJul 10, 2024

  • CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploadi

    MediumCVSS 4.9No exploitEPSS 0%

    hackmd · codimdApr 26, 2025