CVE-2020-11541: Techsmith Snagit

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltrate data under the local Administrator account.

Affected products

  • Techsmith Snagit: from 11.2.1, up to and including 20.0.3

Published 2020-05-08. Last modified 2026-06-17.