Hedgedoc is a collaborative document-editing and note-taking platform whose vulnerability exposure centers on a single, widely deployed product serving teams and organizations. Recurring weaknesses cluster around web-application input handling and access control—including cross-site scripting, file-upload validation, authentication bypass, cross-site request forgery, and information exposure—reflecting the complexity of real-time collaborative editing and user-permission models. A meaningful share of its disclosures reach serious severity, making timely patching important for internet-facing deployments. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hedgedoc over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29475CRITICAL HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file system when exporting a note to PD | Apr 26, 2021 | 10.0 | 30 | NO | NO |
CVE-2020-26287HIGH HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an attacker can inject arbitrary `script` tags in HedgeDoc notes using merma | Dec 29, 2020 | 8.7 | 26 | NO | NO |
CVE-2020-26286HIGH HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticated attacker can upload arbitrary files to the upload storage | Dec 29, 2020 | 7.5 | 24 | NO | NO |
CVE-2023-38487HIGH HedgeDoc is software for creating real-time collaborative markdown notes. Prior to version 1.9.9, the API of HedgeDoc 1 can be used to create notes with an alias matching the ID of | Aug 4, 2023 | 8.2 | 23 | NO | NO |
CVE-2026-25642MEDIUM HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below the /uploads/ endpoint did not use a more strict security-poli | Feb 6, 2026 | 6.1 | 21 | NO | NO |
CVE-2021-39175MEDIUM HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode | Aug 30, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-29503MEDIUM HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scripting attack using the YAML-metadata of a note. An attacker with | May 19, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-29474MEDIUM HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker can read arbitrary `.md` files from the server's filesystem due to an improper inpu | Apr 26, 2021 | 5.8 | 21 | NO | NO |
CVE-2021-21259MEDIUM HedgeDoc is open source software which lets you create real-time collaborative markdown notes. In HedgeDoc before version 1.7.2, an attacker can inject arbitrary JavaScript into a | Jan 22, 2021 | 6.1 | 20 | NO | NO |
CVE-2024-45308MEDIUM HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or MariaDB, it is possible to create notes with an alias matching | Sep 2, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hedgedoc.
Media articles that mention a CVE ID that affects a product developed by Hedgedoc — matched by CVE ID, not by vendor name.