VendorsDocsifyjsdocsifyall versions
Vulnerabilities

Docsifyjs Docsify

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2021-23342
Cross-site Scripting (XSS)
Published 2021-02-19 · Modified
8.6EPSS 0.017
CVE-2020-7680
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary JavaScript/HTML inside docsify page.
Published 2020-07-20 · Modified
6.11 PoCEPSS 0.045
CVE-2021-30074
docsify 4.12.1 is affected by Cross Site Scripting (XSS) because the search component does not appropriately encode Code Blocks and mishandles the " character.
Published 2021-04-02 · Modified
6.1EPSS 0.008