Vulnerabilities/

Joplin Cross-site Scripting vulnerability (GHSA-7grw-xfx6-qhx6)

Severity:
Medium

Description

Joplin before 2.11.5 allows XSS via a USE element in an SVG document.

Recommendation

Update the joplin package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
joplin
Anything's wrong? Let us know Last updated on November 10, 2023

This issue is available in SmartScanner Professional

See Pricing