Total vulnerabilities in the database
Versions 0.3.7 and earlier of marked When mangling is disabled via option mangle don't escape target href. This allow attacker to inject arbitrary html-event into resulting a tag.
No technical information available.
No CWE or OWASP classifications available.