VendorsHackMDcodimdall versions
Vulnerabilities

HackMD CodiMD

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-38354
Cross-site Scripting in Hackmd.io Notes lead by HTML Injection
Published 2024-07-10 · Modified
8.1EPSS 0.004
CVE-2024-22778
HackMD CodiMD <2.5.2 is vulnerable to Denial of Service.
Published 2024-02-21 · Analyzed
7.5EPSS 0.007
CVE-2019-15499
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.
Published 2019-08-23 · Modified
6.1EPSS 0.009
CVE-2024-38353
CodiMD - Missing Image Access Controls and Unauthorized Image Access
Published 2024-07-10 · Analyzed
5.3EPSS 0.011
CVE-2025-46654
CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.
Published 2025-04-26 · Analyzed
4.9EPSS 0.003