Skip to content
Noroxi

python-markdown2 project records

3 published records for vendor python-markdown2 project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 20

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

3 records
  • python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds.

    MediumCVSS 6.1No exploitEPSS 2%

    python-markdown2 project · python-markdown2Apr 20, 2020

  • CVE-2018-5773
    24Monitor

    An issue was discovered in markdown2 (aka python-markdown2) through 2.3.5.

    MediumCVSS 6.1No exploitEPSS 1%

    python-markdown2 project · python-markdown2Jan 18, 2018

  • CVE-2009-3724
    24Monitor

    python-markdown2 before 1.0.1.14 has multiple cross-site scripting (XSS) issues.

    MediumCVSS 6.1No exploitEPSS 1%

    python-markdown2 project · python-markdown2Jan 15, 2020