Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mistune HIGH 7.5
CVE-2026-59925

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emph…

Fix: 3.3.0+
Fix from $1,950 2026-07-08
Mistune HIGH 7.5
CVE-2026-59928

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-li…

Fix: 3.3.0+
Fix from $1,950 2026-07-08
Mistune MEDIUM 6.1
CVE-2026-59926

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatena…

Fix: 3.3.0+
Fix from $1,600 2026-07-08
Mistune MEDIUM 6.1
CVE-2026-59929

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only java…

Fix: 3.3.0+
Fix from $1,600 2026-07-08
Mistune MEDIUM 5.9
CVE-2026-59924

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths with…

Fix: 3.3.0+
Fix from $1,600 2026-07-08
Mistune MEDIUM 5.3
CVE-2026-59927

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects on…

Fix: 3.3.0+
Fix from $1,600 2026-07-08
Mistune HIGH 7.5
CVE-2026-59922

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a ch…

Fix: 3.3.0+
Fix from $1,950 2026-07-08
Mistune MEDIUM 6.1
CVE-2026-59923

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URI…

Fix: 3.3.0+
Fix from $1,600 2026-07-08
Mistune MEDIUM 6.1
CVE-2026-44896

Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() functio…

Fix: after 3.2.0
Fix from $1,600 2026-05-26
Mistune MEDIUM 6.1
CVE-2026-44897

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concaten…

Fix: 3.2.1+
Fix from $1,600 2026-05-26
Mistune MEDIUM 6.1
CVE-2026-44898

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (…

Fix: 3.2.1+
Fix from $1,600 2026-05-26
Mistune MEDIUM 6.1
CVE-2026-44899

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options…

Fix: 3.2.1+
Fix from $1,600 2026-05-26
Mistune MEDIUM 6.1
CVE-2026-44708

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($…

Fix: 3.2.1+
Fix from $1,600 2026-05-26
Mistune MEDIUM 6.1
CVE-2017-15612

mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and aut…

Patch available
Fix from $1,600 2017-10-19