MEDIUM6.1npm
GHSA-22g5-r2x5-97cx· CVE-2026-59710showdown allows stored cross-site scripting through table header ID injection
Modified: 9/10/2026
package
pkg:npm/showdown
showdown allows stored cross-site scripting through table header ID injection
Modified: 9/10/2026
showdown metadata title handling allows cross-site scripting
Modified: 9/10/2026
Reverse Tabnabbing in showdown
Modified: 10/1/2021
Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing
Modified: 9/10/2026