Ipandao maintains a focused web-based markdown editor product, editor.md, that achieves notable prominence despite a narrow portfolio footprint. Vulnerabilities affecting this product recur around cross-site scripting and related input-neutralization weaknesses, reflecting the web-rendering surface inherent to a collaborative editor. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipandao over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-19697MEDIUM Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the <iframe>src parameter. | Apr 4, 2023 | 6.1 | 22 | NO | NO |
CVE-2018-16330MEDIUM Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element. | Sep 2, 2018 | 6.1 | 22 | NO | NO |
CVE-2020-19660MEDIUM Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values. | May 8, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-29641MEDIUM Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text. | May 1, 2023 | 6.1 | 21 | NO | NO |
CVE-2020-19698MEDIUM Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter. | Apr 4, 2023 | 6.1 | 21 | NO | NO |
CVE-2019-14653MEDIUM pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element. | Aug 3, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-9737MEDIUM Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring. | Mar 13, 2019 | 6.1 | 21 | NO | NO |
CVE-2018-19056MEDIUM pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element. | Nov 7, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipandao.
Media articles that mention a CVE ID that affects a product developed by Ipandao — matched by CVE ID, not by vendor name.