Hedgedoc

Hedgedoc

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 06.02.2026 19:23:59
  • Zuletzt bearbeitet 25.02.2026 14:45:01

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below the /uploads/ endpoint did not use a more strict security-policy. This resulted in a too open Content-Security-Policy and furthermor...

  • EPSS 0.02%
  • Veröffentlicht 05.12.2025 22:47:44
  • Zuletzt bearbeitet 09.12.2025 16:37:38

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OAuth2 endpoints for social login providers such as Google, GitHub, GitLab, Facebook or Dropbox lack CSRF protection, since they don...

  • EPSS 0.14%
  • Veröffentlicht 10.04.2025 13:11:48
  • Zuletzt bearbeitet 17.09.2025 18:24:46

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.3, a malicious SVG file uploaded to HedgeDoc results in the possibility of XSS when opened in a new tab instead of the editor itself. The XSS is possible ...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 02.09.2024 18:15:37
  • Zuletzt bearbeitet 22.09.2025 17:27:13

HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or MariaDB, it is possible to create notes with an alias matching the ID of existing notes. The affected existing note can then not be ...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 04.08.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 08:13:40

HedgeDoc is software for creating real-time collaborative markdown notes. Prior to version 1.9.9, the API of HedgeDoc 1 can be used to create notes with an alias matching the ID of existing notes. The affected existing note can then not be accessed a...

  • EPSS 0.31%
  • Veröffentlicht 11.04.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:12

HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version 1.9.1 and later have an enumerable filename after the upload, resulting in potential information leakage of uploaded documents. T...

  • EPSS 0.31%
  • Veröffentlicht 30.08.2021 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:47

HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode feature by embedding an iframe hosting the malicious code into the sl...

  • EPSS 2.05%
  • Veröffentlicht 19.05.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:01:15

HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scripting attack using the YAML-metadata of a note. An attacker with write access to a note can embed HTML tags in the Open Graph metadata...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 26.04.2021 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:01:11

HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker can read arbitrary `.md` files from the server's filesystem due to an improper input validation, which results in the ability to perform a relative path ...

  • EPSS 0.26%
  • Veröffentlicht 26.04.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:01:12

HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file system when exporting a note to PDF. Since the code injection has to take place as note content, there f...