← Back

Zettlr

zettlr

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Zettlr
zettlr

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zettlr
1Zettlr
Jun 17, 2026
Nov 3, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Zettlr. This is possible because the application does not ha...Show more
Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Zettlr. This is possible because the application does not have a CSP policy (or at least not strict enough) and/or does not properly validate the contents of markdown files before rendering them.Show less
1Zettlr
1Zettlr
Jun 17, 2026
Jun 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
No filtering of cross-site scripting (XSS) payloads in the markdown-editor in Zettlr 1.8.7 allows attackers to perform remote code execution via a crafted file.
1Zettlr
1Zettlr
Jun 17, 2026
May 27, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Zettlr from 0.20.0 to 1.8.8 allows an attacker to execute an arbitrary script by loading a file or code snippet containing an invalid iframe into Zettlr.