Marked

Vendor:

First CVE: Jan 27, 2015 · Active for 11 years

11
Total CVEs
More Total CVEs than 89% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Marked over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 27, 2015
11 years ago
Most Recent CVE
Apr 24, 2026
91 days ago

CVE Severity & Scoring

Marked11 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (90.9%)
Unknown1 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High0 (0.0%)
Unknown1 (9.1%)
User Interaction
None7 (63.6%)
Unknown1 (9.1%)
Required3 (27.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (90.9%)
Unknown1 (9.1%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a
Apr 24, 20267.530NONO
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead t
Jan 14, 20227.526NONO
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular
Jan 14, 20227.526NONO
Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service
Feb 8, 20217.523NONO
The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characters can block for around 6 seconds.
Jun 7, 20187.523NONO
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
Jan 2, 20186.122NONO
marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parses input, specifically HTML entities, it's possible to bypass
May 31, 20186.121NONO
Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsi
May 23, 20257.520NONO
The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue
Jan 23, 20177.520NONO
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related
Jan 6, 20206.119NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Marked

Top CWEs

Versions

No cataloged versions.