Vendorsmarked projectmarkedany version
Vulnerabilities

marked project marked any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2026-41680
Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizer
Published 2026-04-24 · Analyzed
8.7EPSS 0.005
CVE-2015-8854
The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue for the em inline rule," aka a "regular expression denial of service (ReDoS)."
Published 2017-01-23 · Modified
7.8EPSS 0.043
CVE-2022-21680
Cubic catastrophic backtracking (ReDoS) in marked
Published 2022-01-14 · Modified
7.5EPSS 0.028
CVE-2022-21681
Exponential catastrophic backtracking (ReDoS) in marked
Published 2022-01-14 · Modified
7.5EPSS 0.027
CVE-2021-21306
Denial of Service in Marked
Published 2021-02-08 · Modified
7.5EPSS 0.025
CVE-2017-16114
The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characters can block for around 6 seconds.
Published 2018-06-07 · Modified
7.5EPSS 0.018
CVE-2018-25110
Regular Expression Denial of Service (ReDoS) in markedjs/marked
Published 2025-05-23 · Analyzed
7.5EPSS 0.006
CVE-2014-3743
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's.
Published 2020-01-06 · Modified
6.1EPSS 0.017
CVE-2017-1000427
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
Published 2018-01-02 · Modified
6.1EPSS 0.015
CVE-2016-10531
marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parses input, specifically HTML entities, it's possible to bypass marked's content injection protection (`sanitize: true`) to inject a `javascript:` URL. This flaw exists because `&#xNNanything;` gets parsed to what it could and leaves the rest behind, resulting in just `anything;` being left.
Published 2018-05-31 · Modified
6.1EPSS 0.015
CVE-2015-1370
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.
Published 2015-01-27 · Modified
4.3EPSS 0.021