CVE-2021-47839

Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Marky 0.0.1 contiene una vulnerabilidad persistente de cross-site scripting que permite a los atacantes inyectar scripts maliciosos en archivos markdown. Los atacantes pueden subir archivos markdown manipulados con cargas útiles de JavaScript incrustadas que se ejecutan cuando se abre el archivo, lo que podría permitir la ejecución remota de código.

16 Jan 2026, 22:16

Type Values Removed Values Added
References () https://www.vulncheck.com/advisories/marky-persistent-cross-site-scripting - () https://www.vulncheck.com/advisories/marky-persistent-cross-site-scripting -

16 Jan 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 19:16

Updated : 2026-04-15 00:35


NVD link : CVE-2021-47839

Mitre link : CVE-2021-47839

CVE.ORG link : CVE-2021-47839


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')