Filtered by vendor Hackmdio Subscriptions
Filtered by product Codimd Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-46654 1 Hackmdio 1 Codimd 2025-06-16 4.9 Medium
CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.