Python Markdown2

Vendor:

First CVE: Jan 18, 2018 · Active for 8 years

3
Total CVEs
More Total CVEs than 64% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Python Markdown2 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2018
8 years ago
Most Recent CVE
Apr 20, 2020
2,286 days ago

CVE Severity & Scoring

Python Markdown23 CVEs
All CVEs352,231 CVEs
Medium
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required3 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
python-markdown2 before 1.0.1.14 has multiple cross-site scripting (XSS) issues.
Jan 15, 20206.122NONO
An issue was discovered in markdown2 (aka python-markdown2) through 2.3.5. The safe_mode feature, which is supposed to sanitize user input against XSS, is flawed and does not escap
Jan 18, 20186.121NONO
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an on
Apr 20, 20206.117NONO

Exploit Exposure

Signals from CVEs in this product scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (3 CVEs).

Media Mentions

Signals from CVEs in this product scope (3 CVEs).

Top CNAs Publishing CVEs For Python Markdown2

Top CWEs

Versions

No cataloged versions.