VYPR
Vendor

Markdown PDF Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2023-0835HigApr 4, 2023
    risk 0.53cvss 8.2epss 0.01

    markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user.

  • CVE-2018-3770MedJul 20, 2018
    risk 0.36cvss 5.5epss 0.01

    A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.