CVE-2026-25642
- EPSS 0.03%
- Veröffentlicht 06.02.2026 19:23:59
- Zuletzt bearbeitet 25.02.2026 14:45:01
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below the /uploads/ endpoint did not use a more strict security-policy. This resulted in a too open Content-Security-Policy and furthermor...
CVE-2025-66629
- EPSS 0.02%
- Veröffentlicht 05.12.2025 22:47:44
- Zuletzt bearbeitet 09.12.2025 16:37:38
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OAuth2 endpoints for social login providers such as Google, GitHub, GitLab, Facebook or Dropbox lack CSRF protection, since they don...
CVE-2025-32391
- EPSS 0.14%
- Veröffentlicht 10.04.2025 13:11:48
- Zuletzt bearbeitet 17.09.2025 18:24:46
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.3, a malicious SVG file uploaded to HedgeDoc results in the possibility of XSS when opened in a new tab instead of the editor itself. The XSS is possible ...
CVE-2024-45308
- EPSS 0.14%
- Veröffentlicht 02.09.2024 18:15:37
- Zuletzt bearbeitet 22.09.2025 17:27:13
HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or MariaDB, it is possible to create notes with an alias matching the ID of existing notes. The affected existing note can then not be ...
CVE-2023-38487
- EPSS 0.07%
- Veröffentlicht 04.08.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:13:40
HedgeDoc is software for creating real-time collaborative markdown notes. Prior to version 1.9.9, the API of HedgeDoc 1 can be used to create notes with an alias matching the ID of existing notes. The affected existing note can then not be accessed a...
CVE-2022-24837
- EPSS 0.31%
- Veröffentlicht 11.04.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:12
HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version 1.9.1 and later have an enumerable filename after the upload, resulting in potential information leakage of uploaded documents. T...
CVE-2021-39175
- EPSS 0.31%
- Veröffentlicht 30.08.2021 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:18:47
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode feature by embedding an iframe hosting the malicious code into the sl...
CVE-2021-29503
- EPSS 2.05%
- Veröffentlicht 19.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:15
HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scripting attack using the YAML-metadata of a note. An attacker with write access to a note can embed HTML tags in the Open Graph metadata...
CVE-2021-29474
- EPSS 0.28%
- Veröffentlicht 26.04.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:11
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker can read arbitrary `.md` files from the server's filesystem due to an improper input validation, which results in the ability to perform a relative path ...
- EPSS 0.26%
- Veröffentlicht 26.04.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:12
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file system when exporting a note to PDF. Since the code injection has to take place as note content, there f...