Editor.Md

Vendor:

First CVE: Sep 2, 2018 · Active for 7 years

8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Editor.Md over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 2, 2018
7 years ago
Most Recent CVE
May 8, 2023
1,172 days ago

CVE Severity & Scoring

Editor.Md8 CVEs
All CVEs352,101 CVEs
Medium
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required8 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the <iframe>src parameter.
Apr 4, 20236.122NONO
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.
Sep 2, 20186.122NONO
Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values.
May 8, 20236.121NONO
Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text.
May 1, 20236.121NONO
Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter.
Apr 4, 20236.121NONO
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
Aug 3, 20196.121NONO
Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
Mar 13, 20196.121NONO
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
Nov 7, 20186.121NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Editor.Md

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.5.076.10.7%00