CVE-2017-6589: Epiceditor Project Epiceditor

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document.

Affected products

Published 2017-03-09. Last modified 2026-06-17.