VYPR

Zettlr

by Zettlr

CVEs (3)

  • CVE-2021-26835MedJun 18, 2021
    risk 0.40cvss 6.1epss 0.01

    No filtering of cross-site scripting (XSS) payloads in the markdown-editor in Zettlr 1.8.7 allows attackers to perform remote code execution via a crafted file.

  • CVE-2021-20727MedMay 27, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Zettlr from 0.20.0 to 1.8.8 allows an attacker to execute an arbitrary script by loading a file or code snippet containing an invalid iframe into Zettlr.

  • CVE-2022-40276MedNov 3, 2022
    risk 0.36cvss 5.5epss 0.00

    Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Zettlr. This is possible because the application does not have a CSP policy (or at least not strict enough) and/or does…