Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

hedgedoc — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in hedgedoc, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with Hedgedoc, an open-source collaborative markdown editor, focusing on weakness types such as cross-site scripting and information disclosure. It collects known issues reported between 2020 and 2024, covering critical and medium-severity flaws that affect the application's integrity, confidentiality, and availability. Here, you can track the vendor's historical advisories to understand how security updates were deployed over time, analyze specific weakness classes to see how they manifest in real-world collaborative editing environments, and look up the product’s vulnerability history to assess its current security posture. The data provides a comprehensive view of past incidents, helping developers and users identify patterns in defect introduction and resolution. By reviewing these records, stakeholders can better evaluate the risks associated with deploying Hedgedoc in production environments and understand the effectiveness of mitigation strategies implemented by the maintainers. This resource serves as a neutral reference for security professionals, enabling them to benchmark the product against industry standards and make informed decisions regarding deployment and maintenance. The aggregated information is derived from public advisories, CVE entries, and community reports, ensuring a transparent and verifiable record of the product's security journey without speculation or bias.

Vendor: hedgedoc

CVE ID Title CVSS Severity Published
CVE-2026-58489 HedgeDoc: CSRF in GitHub Gist export callback CWE-352 - - 2026-07-13
CVE-2026-58486 HedgeDoc: Denial-of-service via YAML alias expansion in note frontmatter CWE-400 - - 2026-07-13
CVE-2026-58487 HedgeDoc: Stored HTML injection via email local-part CWE-79 - - 2026-07-13
CVE-2026-58488 HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing CWE-290 - - 2026-07-13
CVE-2026-25642 HedgeDoc security headers for uploaded files were not working CWE-79 4.3 Medium 2026-02-06
CVE-2025-66629 HedgeDoc is missing state parameter in OAuth2 flows could lead to CSRF CWE-352 3.7 Low 2025-12-05
CVE-2025-32391 HedgeDoc allows XSS possibility through malicious SVG uploads CWE-79 6.4 Medium 2025-04-10
CVE-2024-45308 MySQL & free URL mode allows to hide existing notes in hedgedoc CWE-1289 6.5 Medium 2024-09-02
CVE-2023-38487 HedgeDoc API allows to hide existing notes CWE-289 6.5 Medium 2023-08-04
CVE-2022-24837 Enumerable upload file names in hedgedoc CWE-200 5.3 Medium 2022-04-11
CVE-2021-39175 XSS vector in slide mode speaker-view CWE-74 8.1 High 2021-08-30
CVE-2021-29503 Improper Neutralization of Script-Related HTML Tags in Notes CWE-80 8.1 High 2021-05-19
CVE-2021-29474 Relative Path Traversal Attack on note creation CWE-20 4.7 Medium 2021-04-26
CVE-2021-29475 PDF export allows arbitrary file reads CWE-94 10.0 Critical 2021-04-26
CVE-2021-21259 Stored XSS in slide mode CWE-79 7.4 High 2021-01-22
CVE-2020-26287 Stored XSS in mermaid diagrams CWE-79 8.7 High 2020-12-28
CVE-2020-26286 Arbitary file upload CWE-434 7.5 High 2020-12-28

All 17 known CVE vulnerabilities affecting hedgedoc with full Chinese analysis, references, and POCs where available.