CVE-2025-6492
- EPSS 0.06%
- Veröffentlicht 22.06.2025 20:00:14
- Zuletzt bearbeitet 23.06.2025 20:16:21
A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected by this vulnerability is the function getRecommendTitleFromMarkdownString of the file marktext/src/main/utils/index.js. The manipulation leads to ineffici...
CVE-2023-2318
- EPSS 0.06%
- Veröffentlicht 19.08.2023 06:15:46
- Zuletzt bearbeitet 21.11.2024 07:58:22
DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows arbitrary JavaScript code to run in the context of MarkText main window. This vulnerability can be exploited if a user copies tex...
CVE-2023-1004
- EPSS 0.17%
- Veröffentlicht 24.02.2023 08:15:11
- Zuletzt bearbeitet 21.11.2024 07:38:16
A vulnerability has been found in MarkText up to 0.17.1 on Windows and classified as critical. Affected by this vulnerability is an unknown functionality of the component WSH JScript Handler. The manipulation leads to code injection. Local access is ...
CVE-2022-21158
- EPSS 0.2%
- Veröffentlicht 10.03.2022 17:45:09
- Zuletzt bearbeitet 21.11.2024 06:44:00
A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: scheme) inside the document may allow an attacker to execute an arbitrary script on the PC of the user using mark...
CVE-2022-25069
- EPSS 1.34%
- Veröffentlicht 05.03.2022 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:36
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.
- EPSS 1.2%
- Veröffentlicht 29.01.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:49:51
MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code Execution via a .md file containing a mutation Cross-Site Scripting (XSS) payload.
CVE-2021-29996
- EPSS 3.22%
- Veröffentlicht 05.04.2021 08:15:12
- Zuletzt bearbeitet 21.11.2024 06:02:08
Mark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by opening .md files containing a mutation Cross Site Scripting (XSS) payload.
CVE-2020-27176
- EPSS 1.29%
- Veröffentlicht 16.10.2020 05:15:11
- Zuletzt bearbeitet 21.11.2024 05:20:49
Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the design of the "source code mode" feature, which pars...