The Python Markdown2 Project maintains a lightweight markup-conversion library whose vulnerability footprint, though modest in volume, reflects its role in parsing and rendering untrusted text across a variety of applications and build systems. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Python Markdown2 Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3724MEDIUM python-markdown2 before 1.0.1.14 has multiple cross-site scripting (XSS) issues. | Jan 15, 2020 | 6.1 | 22 | NO | NO |
CVE-2018-5773MEDIUM An issue was discovered in markdown2 (aka python-markdown2) through 2.3.5. The safe_mode feature, which is supposed to sanitize user input against XSS, is flawed and does not escap | Jan 18, 2018 | 6.1 | 21 | NO | NO |
CVE-2020-11888MEDIUM python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an on | Apr 20, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Python Markdown2 Project.
Media articles that mention a CVE ID that affects a product developed by Python Markdown2 Project — matched by CVE ID, not by vendor name.