simple-markdown
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting simple-markdownpage 1 of 1
- CVE-2019-25102MEDIUMCVSS 4.3EG 4.3✓ Fixed in 0.6.12023-02-12
A vulnerability, which was classified as problematic, was found in simple-markdown 0.6.0. Affected is an unknown function of the file simple-markdown.js. The manipulation with the input <<<<<<<<<<:/:/:/:/:/:/:/:/:/:/ leads to inefficient r…
- CVE-2019-25103MEDIUMCVSS 4.3EG 4.3✓ Fixed in 0.5.22023-02-12
A vulnerability has been found in simple-markdown 0.5.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file simple-markdown.js. The manipulation leads to inefficient regular expression comp…
- CVE-2019-9844MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.4.42019-04-09
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
Check whether simple-markdown is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for simple-markdown CVEs against the assets you own.
Start Free Scan →