Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.1
CVE-2026-104477
- EPSS 0.19%
- Veröffentlicht 02.10.2026 23:28:47
- Zuletzt bearbeitet 06.10.2026 16:00:36
Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images c...
5.3
CVE-2024-1899
- EPSS 0.8%
- Veröffentlicht 26.02.2024 19:15:07
- Zuletzt bearbeitet 18.09.2025 16:25:27
An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of service conditions.
1