Markdown It Project maintains a focused markdown parsing library widely embedded in documentation systems, static site generators, and content platforms across the software supply chain. Despite its narrow product scope, the library's parsing role and deep integration into downstream applications mean that vulnerabilities here warrant attention from maintainers of dependent projects. Current CVE counts, severity distribution, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Markdown It Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2327HIGH Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify f | Feb 12, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-48988MEDIUM markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the | Jun 17, 2026 | 5.3 | 24 | NO | NO |
CVE-2015-10005HIGH A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation leads | Dec 27, 2022 | 7.5 | 23 | NO | NO |
CVE-2022-21670MEDIUM markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should u | Jan 10, 2022 | 5.3 | 21 | NO | NO |
CVE-2025-7969MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is as | Aug 21, 2025 | 6.1 | 19 | NO | NO |
CVE-2015-3295MEDIUM markdown-it before 4.1.0 does not block data: URLs. | Jun 7, 2017 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Markdown It Project.
Media articles that mention a CVE ID that affects a product developed by Markdown It Project — matched by CVE ID, not by vendor name.