Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

markedjs — Vulnerabilities & Security Advisories 4

Browse all 4 CVE security advisories affecting markedjs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Markedjs is a JavaScript Markdown parser and compiler that converts Markdown to HTML, primarily used for content rendering in web applications. Historically, it has been susceptible to cross-site scripting (XSS) vulnerabilities due to improper input sanitization, with four CVEs recorded. These issues often stem from insecure handling of user-provided Markdown content, allowing attackers to inject malicious scripts. While no major public incidents have been widely reported, the consistent pattern of XSS vulnerabilities highlights the importance of implementing proper output encoding and context-aware sanitization when using this library in security-sensitive applications.

Top products by markedjs: marked

This page lists every published CVE security advisory associated with markedjs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.