CVE-2021-47836
Markdown Explorer 0.1.1 - Persistent Cross-Site Scripting
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
4th
Markdown Explorer 0.1.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through file uploads and editor inputs. Attackers can upload markdown files with embedded JavaScript payloads that execute in the application's privileged renderer context, allowing code execution on the host.
| CWE | CWE-79 |
| Vendor | jersou |
| Product | markdown explorer |
| Published | Jan 16, 2026 |
| Last Updated | May 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for jersou markdown explorer
Be the first to know when new medium vulnerabilities affecting jersou markdown explorer are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
jersou / Markdown Explorer
0.1.1
References
Credits
TaurusOmar