Skip to content
Noroxi

MarkText records

7 published records for vendor marktext.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
4
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 20
  2. 21
  3. 22
  4. 23

Bar: total · dark part: CISA KEV.

Attack profile

All records

7 records
  • Mark Text through 0.16.3 allows attackers arbitrary command execution.

    CriticalCVSS 9.6No exploitEPSS 3%

    marktext · marktextApr 5, 2021

  • Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote co

    CriticalCVSS 9.6No exploitEPSS 2%

    marktext · marktextMar 4, 2022

  • Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution.

    CriticalCVSS 9.6No exploitEPSS 2%

    marktext · marktextOct 16, 2020

  • CVE-2023-2318
    38Monitor

    MarkText DOM-Based Cross-site Scripting leading to Remote Code Execution

    CriticalCVSS 9.6No exploitEPSS 1%

    marktext · marktextAug 19, 2023

  • MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering.

    CriticalCVSS 9.0No exploitEPSS 2%

    marktext · marktextJan 29, 2022

  • CVE-2023-1004
    31Monitor

    MarkText WSH JScript code injection

    HighCVSS 7.8No exploitEPSS 0%

    marktext · marktextFeb 24, 2023

  • A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: sch

    MediumCVSS 5.4No exploitEPSS 1%

    marktext · marktextMar 10, 2022