Docsifyjs

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-30074

    docsify 4.12.1 is affected by Cross Site Scripting (XSS) because the search component does not appropriately encode Code Blocks and mishandles the " character.

    Last Modified: Nov 21, 2024
    Published: Apr 02, 2021

    CVE-2021-23342

    Cross-site Scripting (XSS)

    Last Modified: Nov 21, 2024
    Published: Feb 19, 2021

    CVE-2020-7680

    docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary JavaScript/HTML inside docsify page.

    Last Modified: Nov 21, 2024
    Published: Jul 20, 2020
    Items Per Page
    Docsifyjs Vulnerabilities & Security CVEs | CVE-DB