Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hedgedoc

First CVE: Dec 29, 2020Active for: 6 yearsTotal CVEs: 13
24.2
VTI Score
Low

Hedgedoc is a collaborative document-editing and note-taking platform whose vulnerability exposure centers on a single, widely deployed product serving teams and organizations. Recurring weaknesses cluster around web-application input handling and access control—including cross-site scripting, file-upload validation, authentication bypass, cross-site request forgery, and information exposure—reflecting the complexity of real-time collaborative editing and user-permission models. A meaningful share of its disclosures reach serious severity, making timely patching important for internet-facing deployments. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hedgedoc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 29, 2020
5 years ago
Most Recent CVE
Feb 6, 2026
168 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-29475CRITICAL
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file system when exporting a note to PD
Apr 26, 202110.030NONO
CVE-2020-26287HIGH
HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an attacker can inject arbitrary `script` tags in HedgeDoc notes using merma
Dec 29, 20208.726NONO
CVE-2020-26286HIGH
HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticated attacker can upload arbitrary files to the upload storage
Dec 29, 20207.524NONO
CVE-2023-38487HIGH
HedgeDoc is software for creating real-time collaborative markdown notes. Prior to version 1.9.9, the API of HedgeDoc 1 can be used to create notes with an alias matching the ID of
Aug 4, 20238.223NONO
CVE-2026-25642MEDIUM
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below the /uploads/ endpoint did not use a more strict security-poli
Feb 6, 20266.121NONO
CVE-2021-39175MEDIUM
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode
Aug 30, 20216.121NONO
CVE-2021-29503MEDIUM
HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scripting attack using the YAML-metadata of a note. An attacker with
May 19, 20216.121NONO
CVE-2021-29474MEDIUM
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker can read arbitrary `.md` files from the server's filesystem due to an improper inpu
Apr 26, 20215.821NONO
CVE-2021-21259MEDIUM
HedgeDoc is open source software which lets you create real-time collaborative markdown notes. In HedgeDoc before version 1.7.2, an attacker can inject arbitrary JavaScript into a
Jan 22, 20216.120NONO
CVE-2024-45308MEDIUM
HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or MariaDB, it is possible to create notes with an alias matching
Sep 2, 20246.519NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
69%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None6 (46.2%)
Unknown0 (0.0%)
Required7 (53.8%)
Privileges Required
Low2 (15.4%)
High0 (0.0%)
None11 (84.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hedgedoc.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hedgedoc — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hedgedoc's Products

View all 1 CNAs →

Top CWEs