361,800
Total CVEs
26,223
Critical
85,816
High
1,626
CISA KEV
0
This Week
4 results · Page 1/1
In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks.
issuehunt
There is XSS in browser/components/MarkdownPreview.js in BoostIO Boostnote 0.11.15 via a label named flowchart, sequence, gallery, or chart, as demonstrated by a crafted SRC attribute of an IFRAME element, a different vulnerability than CVE-2019-12136.
boostio
There is XSS in BoostIO Boostnote 0.11.15 via a label named mermaid, as demonstrated by a crafted SRC attribute of an IFRAME element.
boostio
Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element.
boostnote