MathJax is a JavaScript display engine for rendering mathematical notation across web browsers and learning platforms, with its vulnerability footprint concentrated in the single widely embedded mathjax library. The recurring weakness classes center on cross-site scripting via improper input neutralization during page generation and inefficient regular expression handling, reflecting the parsing and rendering demands of processing untrusted mathematical markup in web contexts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mathjax over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39663HIGH Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: | Aug 29, 2023 | 7.5 | 22 | NO | NO |
CVE-2018-1999024MEDIUM MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running withi | Jul 23, 2018 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mathjax.
Media articles that mention a CVE ID that affects a product developed by Mathjax — matched by CVE ID, not by vendor name.