VendorsDocsifyjsdocsifyany version
Vulnerabilities

Docsifyjs Docsify any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2021-23342
Cross-site Scripting (XSS)
Published 2021-02-19 · Modified
8.6EPSS 0.017
CVE-2020-7680
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary JavaScript/HTML inside docsify page.
Published 2020-07-20 · Modified
6.11 PoCEPSS 0.045