📦 Hedgedoc

by Hedgedoc

🔍 What is Hedgedoc?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-29475

CRITICAL CVSS 10.0 Apr 26, 2021

CVE-2021-29475 is a critical file disclosure vulnerability in HedgeDoc (formerly CodiMD) where attackers can read arbitrary files from the filesystem when exporting notes to PDF. This affects all Hedg...

CVE-2021-39175

HIGH CVSS 8.1 Aug 30, 2021

CVE-2021-39175 is a cross-site scripting (XSS) vulnerability in HedgeDoc that allows unauthenticated attackers to inject malicious JavaScript into slide-mode speaker notes. This affects all HedgeDoc i...

CVE-2021-29503

HIGH CVSS 8.1 May 19, 2021

This CVE describes a stored cross-site scripting (XSS) vulnerability in HedgeDoc's YAML metadata processing. Attackers with write access to notes can inject malicious JavaScript via Open Graph metadat...

CVE-2026-25642

MEDIUM CVSS 4.3 Feb 6, 2026

This vulnerability in HedgeDoc allows attackers to host malicious interactive web content, such as fake login forms, via SVG files uploaded to the /uploads/ endpoint due to an overly permissive Conten...

CVE-2025-66629

LOW CVSS 3.7 Dec 5, 2025

HedgeDoc versions before 1.10.4 have CSRF vulnerabilities in OAuth2 endpoints for social login providers like Google, GitHub, GitLab, Facebook, and Dropbox. Attackers can trick authenticated users int...