Vulnerabilities (CVE)

Filtered by vendor Hackmdio Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-46654 1 Hackmdio 1 Codimd 2025-06-16 N/A 4.9 MEDIUM
CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.