Medium severity6.1NVD Advisory· Published Jun 18, 2021· Updated Jun 17, 2026
CVE-2021-26835
CVE-2021-26835
Description
No filtering of cross-site scripting (XSS) payloads in the markdown-editor in Zettlr 1.8.7 allows attackers to perform remote code execution via a crafted file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/Zettlr/Zettlr/issues/1716nvdExploitIssue TrackingPatchThird Party Advisory
- github.com/Zettlr/Zettlr/releases/tag/v1.8.9nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.