marked@0.3.3 vulnerabilities

A markdown parser built for speed

Latest version 0.6.2
First published 8 years ago
Latest version published 3 months ago

Licenses detected

  • license: MIT >=0.3.1
Continuously find & fix vulnerabilities like these in your dependencies. Test and protect your applications

Direct Vulnerabilities

Known vulnerabilities in the marked@0.3.3 package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable versions Snyk patch Published
  • M
Regular Expression Denial of Service (ReDoS)
>=0.1.3 <0.6.2 Not available 07 Apr, 2019
  • H
Regular Expression Denial of Service (ReDoS)
<0.3.18 Not available 27 Feb, 2018
  • M
Cross-site Scripting (XSS)
<0.3.9 Not available 25 Dec, 2017
  • H
Cross-site Scripting (XSS)
<0.3.9 Not available 25 Dec, 2017
  • H
Regular Expression Denial of Service (ReDoS)
<0.3.9 Available 21 Sep, 2017
  • H
Cross-site Scripting (XSS) via Data URIs
<0.3.7 Available 30 Jan, 2017
  • H
Content & Code Injection (XSS)
>=0.3.1 <0.3.6 Available 20 Apr, 2016
  • H
Regular Expression Denial of Service (DoS)
<0.3.4 Available 30 Jan, 2014