HackMD's vulnerability footprint concentrates in its collaborative note-taking and markdown documentation platform (CodiMD), with the durable signal centered on web-application input-handling and access-control issues including cross-site scripting, improper path traversal protections, and missing authorization checks. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hackmd over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-38353MEDIUM CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and access control vulnerability allowing an unauthenticated att | Jul 10, 2024 | 5.3 | 25 | NO | YES |
CVE-2019-15499MEDIUM CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL. | Aug 23, 2019 | 6.1 | 21 | NO | NO |
CVE-2024-22778HIGH HackMD CodiMD <2.5.2 is vulnerable to Denial of Service. | Feb 21, 2024 | 7.5 | 19 | NO | NO |
CVE-2024-38354MEDIUM CodiMD allows realtime collaborative markdown notes on all platforms. The notebook feature of Hackmd.io permits the rendering of iframe `HTML` tags with an improperly sanitized `na | Jul 10, 2024 | 6.1 | 18 | NO | NO |
CVE-2025-46654MEDIUM CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploa | Apr 26, 2025 | 4.9 | 17 | NO | NO |
CVE-2025-46655MEDIUM CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-ori | Apr 26, 2025 | 4.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hackmd.
Media articles that mention a CVE ID that affects a product developed by Hackmd — matched by CVE ID, not by vendor name.