Known vulnerabilities in markdown-it
Vendor:
markdown-it
Software:
markdown-it
Software CPE:
cpe:2.3:a:markdown-it:markdown-it:*:*:*:*:*:*:*:*
Website:
https://github.com/markdown-it
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
15.0.1
14.3.1
15.0.0
14.3.0
14.2.0
14.1.1
14.1.0
14.0.0
13.0.2
13.0.1
13.0.0
12.3.2
12.3.1
12.3.0
12.2.0
12.1.0
12.0.6
12.0.5
12.0.4
12.0.3
12.0.2
12.0.1
12.0.0
11.0.1
11.0.0
10.0.0
9.1.0
9.0.1
9.0.0
8.4.2
8.4.1
8.4.0
8.3.2
8.3.1
8.3.0
8.2.2
8.2.1
8.2.0
8.1.0
8.0.1
8.0.0
7.0.1
7.0.0
6.1.1
6.1.0
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
5.1.0
5.0.3
5.0.2
5.0.1
5.0.0
4.4.0
4.3.1
4.3.0
4.2.2
4.2.1
4.2.0
4.1.2
4.1.1
4.1.0
4.0.3
4.0.2
4.0.1
4.0.0
3.1.0
3.0.7
3.0.6
3.0.5
3.0.4
3.0.3
3.0.2
3.0.1
3.0.0
2.2.1
2.2.0
2.1.3
2.1.2
2.1.1
2.1.0
2.0.0
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU146761 - Inefficient Algorithmic Complexity |
CWE-407 | Medium | 14.3.1, 15.0.1 | 02.09.2026 |
SB2026090265 |
||
| #VU132289 - Resource exhaustion CVE-2026-48988 |
CWE-400 | Medium | 14.2.0 | 25.05.2026 |
SB2026052543 |
||
| #VU118195 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-7969 |
CWE-79 | Medium | - | 07.11.2025 |
SB2025110741 SB2025110755 SB2025112543 and 4 more |
||
| #VU127413 - Inefficient Regular Expression Complexity CVE-2022-21670 |
CWE-1333 | Medium | 12.3.2 | 08.01.2022 |
SB2022010804 |