Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Marktext CRITICAL 9.6
CVE-2023-2318

DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows arbitrary JavaScript code to…

Fix: after 0.17.1
Fix from $2,300 2023-08-19
Marktext HIGH 7.8
CVE-2023-1004

A vulnerability has been found in MarkText up to 0.17.1 on Windows and classified as critical. Affected by this vulnerability is an unknown functiona…

Fix: after 0.17.1
Fix from $1,950 2023-02-24
Marktext MEDIUM 5.4
CVE-2022-21158

A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: scheme) insi…

Fix: 0.17.0+
Fix from $1,600 2022-03-10
Marktext CRITICAL 9.6
CVE-2022-25069

Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execut…

Patch available
Fix from $2,300 2022-03-05
Marktext CRITICAL 9.0
CVE-2022-24123

MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code Execution via a .md file cont…

Fix: after 0.16.3
Fix from $2,300 2022-01-29
Marktext CRITICAL 9.6
CVE-2021-29996

Mark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by opening .md files containing…

Fix: after 0.16.3
Fix from $2,300 2021-04-05
Marktext CRITICAL 9.6
CVE-2020-27176

Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; ho…

Fix: after 0.16.2
Fix from $2,300 2020-10-16