ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-46654
CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.

NVD description · AI analysis pending
4.9<1% PoC ×2
  • hackmd codimd
CVE-2024-38354
+1 in the same advisory: …38353
CodiMD allows realtime collaborative markdown notes on all platforms.

CodiMD allows realtime collaborative markdown notes on all platforms. The notebook feature of Hackmd.io permits the rendering of iframe `HTML` tags with an improperly sanitized `name` attribute. This vulnerability enables attackers to perform cross-site scripting (XSS) attacks via DOM clobbering. This vulnerability is fixed in 2.5.4.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • hackmd codimd
CVE-2024-22778
HackMD CodiMD <2.5.2 is vulnerable to Denial of Service.

HackMD CodiMD <2.5.2 is vulnerable to Denial of Service.

NVD description · AI analysis pending
7.5<1% PoC
  • hackmd codimd
CVE-2019-15499
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data:

CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.

NVD description · AI analysis pending
6.1<1% PoC
  • hackmd codimd