This page lists publicly disclosed CVE vulnerabilities affecting matthewwithanm markdownify (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2021-47837 | Markdownify 1.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads within markdown files. Attackers can upload crafted markdown files with embedded scripts that execute when the file is opened, potentially enabling remote code execution. | [email protected] | 5.1 | 0.41% | 2026-01-16 | 2026-06-17 |
| CVE-2025-46656 | python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption. | [email protected] | 2.9 | 0.18% | 2025-04-26 | 2026-06-17 |