Editor.Md
Vendor:
First CVE: Sep 2, 2018 · Active for 7 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Editor.Md over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 2, 2018
7 years ago
Most Recent CVE
May 8, 2023
1,172 days ago
CVE Severity & Scoring
Editor.Md8 CVEs
100%
All CVEs352,101 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required8 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-19697MEDIUM Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the <iframe>src parameter. | Apr 4, 2023 | 6.1 | 22 | NO | NO |
CVE-2018-16330MEDIUM Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element. | Sep 2, 2018 | 6.1 | 22 | NO | NO |
CVE-2020-19660MEDIUM Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values. | May 8, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-29641MEDIUM Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text. | May 1, 2023 | 6.1 | 21 | NO | NO |
CVE-2020-19698MEDIUM Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter. | Apr 4, 2023 | 6.1 | 21 | NO | NO |
CVE-2019-14653MEDIUM pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element. | Aug 3, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-9737MEDIUM Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring. | Mar 13, 2019 | 6.1 | 21 | NO | NO |
CVE-2018-19056MEDIUM pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element. | Nov 7, 2018 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Editor.Md
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.5.0 | 7 | 6.1 | 0.7% | 0 | 0 |