CVE-2015-1370

marked < 0.3.2 - Cross-Site Scripting via VBScript Tag in Link

Title source: llm
STIX 2.1

Description

Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.

References (4)

Core 4

Scores

EPSS 0.0205
EPSS Percentile 79.2%

Details

Status published
Products (2)
marked_project/marked < 0.3.2
npm/marked 0 - 0.3.3npm
Published Jan 27, 2015
Tracked Since Feb 18, 2026