Yuin maintains Goldmark, a Markdown parser library with a focused vulnerability footprint centered on input-handling issues such as cross-site scripting in web page generation contexts. This narrow product scope and vulnerability profile suggest limited but important exposure primarily to applications that integrate the parser for user-supplied content processing.
The number and severity of CVEs published that impact products developed by Yuin over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5160MEDIUM Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalizati | Apr 15, 2026 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yuin.
Media articles that mention a CVE ID that affects a product developed by Yuin — matched by CVE ID, not by vendor name.