Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-46654

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.4%
CVSS Severity
CVSS v3 Score 4.9
Products affected by CVE-2025-46654


Contact Us

Shodan ® - All rights reserved