netlify-cms-widget-markdown@2.11.3 vulnerabilities
Widget for editing markdown in Netlify CMS.
-
latest version
2.15.1
-
latest non vulnerable version
-
first published
6 years ago
-
latest version published
3 years ago
-
licenses detected
- >=0
Direct Vulnerabilities
Known vulnerabilities in the netlify-cms-widget-markdown package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
netlify-cms-widget-markdown is a markdown package for netlify-cms. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). It is possible to insert malicious JavaScript when creating a post using the markdown editor feature. This malicious JavaScript is then stored within the application and is executed when a user visits this webpage. PoC
How to fix Cross-site Scripting (XSS)? Upgrade |
<2.12.9
|