Hedgedoc

Hedgedoc

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 13.07.2026 22:34:51
  • Zuletzt bearbeitet 14.07.2026 16:42:11

HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export flow created an OAuth2  state  value but only checked that it was present rather than validating it against the value expected for...

  • EPSS 0.24%
  • Veröffentlicht 13.07.2026 22:12:37
  • Zuletzt bearbeitet 14.07.2026 16:42:11

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bomb due to unsafe processing of the note frontmatter. HedgeDoc parsed frontmatter with js-yaml.load (j...

  • EPSS 0.36%
  • Veröffentlicht 13.07.2026 21:59:27
  • Zuletzt bearbeitet 15.07.2026 15:16:45

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, due to unsafe handling of the local-part of registered email addresses, HedgeDoc was vulnerable to stored HTML Injection through its publish an...

  • EPSS 0.3%
  • Veröffentlicht 13.07.2026 21:43:14
  • Zuletzt bearbeitet 14.07.2026 16:42:11

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Versions prior to 1.11.0 allowed attackers to circumvent the rate-limiting of the /login and /register routes by spoofing IP addresses. HedgeDoc instances checked for C...

  • EPSS 0.19%
  • Veröffentlicht 06.02.2026 19:23:59
  • Zuletzt bearbeitet 25.02.2026 14:45:01

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below the /uploads/ endpoint did not use a more strict security-policy. This resulted in a too open Content-Security-Policy and furthermor...

  • EPSS 0.1%
  • Veröffentlicht 05.12.2025 22:47:44
  • Zuletzt bearbeitet 09.12.2025 16:37:38

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OAuth2 endpoints for social login providers such as Google, GitHub, GitLab, Facebook or Dropbox lack CSRF protection, since they don...

  • EPSS 0.31%
  • Veröffentlicht 10.04.2025 13:11:48
  • Zuletzt bearbeitet 17.09.2025 18:24:46

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.3, a malicious SVG file uploaded to HedgeDoc results in the possibility of XSS when opened in a new tab instead of the editor itself. The XSS is possible ...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 02.09.2024 18:15:37
  • Zuletzt bearbeitet 22.09.2025 17:27:13

HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or MariaDB, it is possible to create notes with an alias matching the ID of existing notes. The affected existing note can then not be ...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 04.08.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 08:13:40

HedgeDoc is software for creating real-time collaborative markdown notes. Prior to version 1.9.9, the API of HedgeDoc 1 can be used to create notes with an alias matching the ID of existing notes. The affected existing note can then not be accessed a...

  • EPSS 1.11%
  • Veröffentlicht 11.04.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:12

HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version 1.9.1 and later have an enumerable filename after the upload, resulting in potential information leakage of uploaded documents. T...