VYPR

npm package

simple-markdown

pkg:npm/simple-markdown

Vulnerabilities (3)

  • CVE-2019-25103Feb 12, 2023
    affected < 0.5.2fixed 0.5.2

    A vulnerability has been found in simple-markdown 0.5.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file simple-markdown.js. The manipulation leads to inefficient regular expression complexity. The attack can be launched remote

  • CVE-2019-25102Feb 12, 2023
    affected < 0.6.1fixed 0.6.1

    A vulnerability, which was classified as problematic, was found in simple-markdown 0.6.0. Affected is an unknown function of the file simple-markdown.js. The manipulation with the input <<<<<<<<<<:/:/:/:/:/:/:/:/:/:/ leads to inefficient regular expression complexity. It is possi

  • CVE-2019-9844Mar 15, 2019
    affected < 0.4.4fixed 0.4.4

    simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.