mathjax
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mathjaxpage 1 of 1
- CVE-2018-1999024MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.7.42018-07-23
MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running within a web browser. This attack appear to be exploitable via T…
- CVE-2023-39663HIGHCVSS 7.5EG 7.52023-08-29
Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions ar…
Check whether mathjax is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mathjax CVEs against the assets you own.
Start Free Scan →