Docsifyjs maintains Docsify, a lightweight documentation generator that transforms markdown files into single-page applications, and its vulnerability footprint concentrates on client-side rendering and input-handling issues. The durable signal centers on cross-site scripting vulnerabilities arising from improper neutralization of user-controlled input during web page generation, a characteristic risk in markdown-to-HTML pipelines. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Docsifyjs over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7680MEDIUM docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. D | Jul 20, 2020 | 6.1 | 31 | NO | YES |
CVE-2021-30074MEDIUM docsify 4.12.1 is affected by Cross Site Scripting (XSS) because the search component does not appropriately encode Code Blocks and mishandles the " character. | Apr 2, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-23342MEDIUM This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) Whe | Feb 19, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Docsifyjs.
Media articles that mention a CVE ID that affects a product developed by Docsifyjs — matched by CVE ID, not by vendor name.