Marked
This hub aggregates every CVE we track for Marked, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
11
CVEs tracked
0
Critical
6
High
0
In CISA KEV
Severity distribution
HIGH6MEDIUM5
Monthly trend
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
2024-092026-08
Latest CVEs
The 11 most recently published vulnerabilities affecting Marked.
- CVE-2026-41680Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizer7.5
- CVE-2018-25110Regular Expression Denial of Service (ReDoS) in markedjs/marked7.5
- CVE-2022-21681Exponential catastrophic backtracking (ReDoS) in marked7.5
- CVE-2022-21680Cubic catastrophic backtracking (ReDoS) in marked7.5
- CVE-2021-21306Denial of Service in Marked5.3
- CVE-2014-3743Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codebl...6.1
- CVE-2017-16114The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characters can block for around 6 seconds.7.5
- CVE-2016-10531marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parses input, specifically HTML entities, it's possible to bypass marked's content...6.1
- CVE-2017-1000427marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.6.1
- CVE-2015-8854The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue for the em inline...7.5
- CVE-2015-1370Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.4.3
Product normalization is registry-driven with AI assist and human review. How it works