CVE-2020-28249: Joplin Project Joplin

Medium severity, CVSS 6.1. EPSS: 3.1% chance of exploitation in the next 30 days.

Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.

Affected products

Published 2020-11-06. Last modified 2026-06-17.