Medium severity6.1NVD Advisory· Published Aug 3, 2021· Updated Jun 17, 2026
CVE-2021-37916
CVE-2021-37916
Description
Joplin before 2.0.9 allows XSS via button and form in the note body.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
joplinnpm | < 2.0.9 | 2.0.9 |
Affected products
3- Joplin/Joplindescription
Patches
Vulnerability mechanics
References
4- github.com/laurent22/joplin/commit/feaecf765368f2c273bea3a9fa641ff0da7e6b26nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-mrmf-755g-w2vwghsaADVISORY
- github.com/laurent22/joplin/releases/tag/v2.0.9nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-37916ghsaADVISORY
News mentions
0No linked articles in our index yet.