Skip to content
Noroxi

markdown-it project records

6 published records for vendor markdown-it project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
83.3%
Median publish → KEV
No record has entered KEV

All records

6 records
  • markdown-it html_re.js redos

    HighCVSS 7.5No exploitEPSS 1%

    markdown-it project · markdown-itDec 27, 2022

  • CVE-2025-7969
    27Monitor

    Markdown-it 14.1.0 - Cross-site scripting (XSS)

    MediumCVSS 6.9No exploitEPSS 0%

    markdown-it project · markdown-itAug 21, 2025

  • Uncontrolled Resource Consumption in markdown-it

    MediumCVSS 5.3No exploitEPSS 2%

    markdown-it project · markdown-itJan 10, 2022

  • CVE-2026-2327
    22Monitor

    Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the

    MediumCVSS 5.5No exploitEPSS 1%

    markdown-it project · markdown-itFeb 12, 2026

  • CVE-2015-3295
    21Monitor

    markdown-it before 4.1.0 does not block data: URLs.

    MediumCVSS 5.3No exploitEPSS 1%

    markdown-it project · markdown-itJun 7, 2017

  • markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

    MediumCVSS 5.3No exploitEPSS 0%

    markdown-it project · markdown-itJun 17, 2026