CVE-2009-3437

Henriksjokvist Markdown Preview - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the live preview feature in the Markdown Preview module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via "Markdown input."

Scores

EPSS 0.0020
EPSS Percentile 42.4%

Classification

CWE
CWE-79
Status published

Affected Products (2)

henriksjokvist/markdown_preview
n/a/n/a

Timeline

Published Sep 28, 2009
Tracked Since Feb 18, 2026