markdown-it_project 漏洞与 CVE 列表(5)

产品(CPE): — CVE 数: 5

markdown-it_project 漏洞概览

汇总 markdown-it_project 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。

已披露问题常与 跨站脚本与拒绝服务 相关,可能在 软件部署与生产负载 场景中带来 会话劫持 等暴露风险。

相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。

漏洞分布趋势(近 24 个月)

显示 155 CVE 数
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
CVE 摘要 来源 最高 CVSS EPSS % 公开时间 更新时间
CVE-2026-2327 Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers excessive backtracking and may lead to a denial-of-service condition. [email protected] 5.5 0.50% 2026-02-12 2026-02-23
CVE-2025-7969 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/renderer.mjs. This issue affects markdown-it: 14.1.0. NOTE: the Supplier does not consider this issue to be a vulnerability. [email protected] 6.9 0.23% 2025-08-21 2025-12-22
CVE-2015-10005 A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is 89c8620157d6e38f9872811620d25138fc9d1b0d. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216852. [email protected] 3.5 0.95% 2022-12-27 2024-11-21
CVE-2022-21670 markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a patch. There are no known workarounds aside from upgrading. [email protected] 5.3 2.15% 2022-01-10 2024-11-21
CVE-2015-3295 markdown-it before 4.1.0 does not block data: URLs. [email protected] 5.3 1.29% 2017-06-07 2026-05-13
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
cvelogic Threat Intelligence