Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-46654

    CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.

    Last Modified: Aug 05, 2025
    Published: Apr 26, 2025

    CVE-2025-46655

    CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE: it can be considered a user error if AWS is employed for hosting untrusted JavaScript content, but the selected architecture within AWS does not have components that are able to insert Content-Security-Policy headers.

    Last Modified: Apr 15, 2026
    Published: Apr 26, 2025

    CVE-2024-38353

    CodiMD - Missing Image Access Controls and Unauthorized Image Access

    Last Modified: Sep 04, 2025
    Published: Jul 10, 2024

    CVE-2024-38354

    Cross-site Scripting in Hackmd.io Notes lead by HTML Injection

    Last Modified: Nov 21, 2024
    Published: Jul 10, 2024

    CVE-2024-22778

    HackMD CodiMD <2.5.2 is vulnerable to Denial of Service.

    Last Modified: May 06, 2025
    Published: Feb 21, 2024
    Items Per Page
    Hackmd Vulnerabilities & Security CVEs | CVE-DB