CVE-2017-6589: Epiceditor Project Epiceditor
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document.
Affected products
- Epiceditor Project Epiceditor: up to and including 0.2.3
Published 2017-03-09. Last modified 2026-06-17.