Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12480 | CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file. |
Tue, 05 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hackmd
Hackmd codimd |
|
| CPEs | cpe:2.3:a:hackmd:codimd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hackmdio
Hackmdio codimd |
Hackmd
Hackmd codimd |
Mon, 16 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hackmdio
Hackmdio codimd |
|
| CPEs | cpe:2.3:a:hackmdio:codimd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hackmdio
Hackmdio codimd |
Tue, 29 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 26 Apr 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file. | |
| Weaknesses | CWE-424 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-29T15:22:49.333Z
Reserved: 2025-04-26T00:00:00.000Z
Link: CVE-2025-46654
Updated: 2025-04-29T14:06:36.558Z
Status : Analyzed
Published: 2025-04-26T21:15:15.100
Modified: 2025-08-05T15:14:39.230
Link: CVE-2025-46654
No data.
OpenCVE Enrichment
No data.
EUVD