Shd101wyy maintains Markdown Preview Enhanced, a document-rendering extension where the observed vulnerability surface centers on code-injection risks inherent to dynamic markdown processing. The durable exposure pattern reflects the challenge of safely handling user-supplied markup without unintended code execution; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shd101wyy over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-50733HIGH Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects eve | Jun 5, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-49493HIGH Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block content as code via vm.runInNewContext(), allowing arbitrar | Jun 5, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-49492HIGH Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs taken from the markdown document - th | Jun 5, 2026 | 8.8 | 33 | NO | NO |
CVE-2025-65716HIGH An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file. | Feb 16, 2026 | 8.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shd101wyy.
Media articles that mention a CVE ID that affects a product developed by Shd101wyy — matched by CVE ID, not by vendor name.