CVE-2021-37916
https://notcve.org/view.php?id=CVE-2021-37916
Joplin before 2.0.9 allows XSS via button and form in the note body. Joplin versiones anteriores a 2.0.9, permite un ataque XSS por medio del button y form en el cuerpo de la nota • https://github.com/laurent22/joplin/commit/feaecf765368f2c273bea3a9fa641ff0da7e6b26 https://github.com/laurent22/joplin/releases/tag/v2.0.9 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-28249 – Joplin 1.2.6 - 'link' Cross Site Scripting
https://notcve.org/view.php?id=CVE-2020-28249
Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note. Joplin versión 1.2.6 para Desktop, permite un ataque de tipo XSS por medio de un elemento LINK en una nota • https://www.exploit-db.com/exploits/49024 https://github.com/fhlip0/JopinXSS https://github.com/laurent22/joplin/releases • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •