VYPR
Medium severity6.1NVD Advisory· Published Apr 20, 2020· Updated Jun 17, 2026

CVE-2020-11888

CVE-2020-11888

Description

python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
markdown2PyPI
< 2.3.92.3.9

Affected products

5

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.