markdown-it project records
6 published records for vendor markdown-it project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 83.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1333 Inefficient Regular Expression Complexity2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-284 Improper Access Control1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2015-10005No exploit | markdown-it html_re.js redosmarkdown-it project · markdown-it · CWE-1333 | High7.5 | — | 0.9% | Dec 27, 2022 |
27Monitor | CVE-2025-7969No exploit | Markdown-it 14.1.0 - Cross-site scripting (XSS)markdown-it project · markdown-it · CWE-79 | Medium6.9 | — | 0.2% | Aug 21, 2025 |
22Monitor | CVE-2022-21670No exploit | Uncontrolled Resource Consumption in markdown-itmarkdown-it project · markdown-it · CWE-400 | Medium5.3 | — | 2.2% | Jan 10, 2022 |
22Monitor | CVE-2026-2327No exploit | Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the markdown-it project · markdown-it · CWE-1333 | Medium5.5 | — | 0.7% | Feb 12, 2026 |
21Monitor | CVE-2015-3295No exploit | markdown-it before 4.1.0 does not block data: URLs.markdown-it project · markdown-it · CWE-284 | Medium5.3 | — | 1.3% | Jun 7, 2017 |
21Monitor | CVE-2026-48988No exploit | markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operationsmarkdown-it project · markdown-it · CWE-400 | Medium5.3 | — | 0.4% | Jun 17, 2026 |
- CVE-2015-1000530Monitor
markdown-it html_re.js redos
HighCVSS 7.5No exploitEPSS 1%markdown-it project · markdown-itDec 27, 2022
- CVE-2025-796927Monitor
Markdown-it 14.1.0 - Cross-site scripting (XSS)
MediumCVSS 6.9No exploitEPSS 0%markdown-it project · markdown-itAug 21, 2025
- CVE-2022-2167022Monitor
Uncontrolled Resource Consumption in markdown-it
MediumCVSS 5.3No exploitEPSS 2%markdown-it project · markdown-itJan 10, 2022
- CVE-2026-232722Monitor
Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the
MediumCVSS 5.5No exploitEPSS 1%markdown-it project · markdown-itFeb 12, 2026
- CVE-2015-329521Monitor
markdown-it before 4.1.0 does not block data: URLs.
MediumCVSS 5.3No exploitEPSS 1%markdown-it project · markdown-itJun 7, 2017
- CVE-2026-4898821Monitor
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
MediumCVSS 5.3No exploitEPSS 0%markdown-it project · markdown-itJun 17, 2026