zettlr CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

zettlr vulnerability overview

Aggregates CVE and security vulnerability intelligence across all zettlr-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk input validation and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-40276 Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Zettlr. This is possible because the application does not have a CSP policy (or at least not strict enough) and/or does not properly validate the contents of markdown files before rendering them. [email protected] 5.5 0.14% 2022-11-03 2025-05-02
CVE-2021-26835 No filtering of cross-site scripting (XSS) payloads in the markdown-editor in Zettlr 1.8.7 allows attackers to perform remote code execution via a crafted file. [email protected] 6.1 0.82% 2021-06-18 2024-11-21
CVE-2021-20727 Cross-site scripting vulnerability in Zettlr from 0.20.0 to 1.8.8 allows an attacker to execute an arbitrary script by loading a file or code snippet containing an invalid iframe into Zettlr. [email protected] 6.1 0.30% 2021-05-27 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence