Skip to main content

Vendor/product archive

markdown-it_project / markdown-it CVEs

Beta · best-effort

6 CVEs tagged to markdown-it_project / markdown-it0 Critical, 0 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2026-48988

Published Jun 17, 2026

markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in th…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-2327

Published Feb 12, 2026

Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2025-7969

Published Aug 21, 2025

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is a…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-10005

Published Dec 27, 2022

A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation lead…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-21670

Published Jan 10, 2022

markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1