Joplin through 1.0.184 allows Arbitrary File Read via XSS.
| Software | From | Fixed in |
|---|---|---|
| joplin_project / joplin | - | 1.0.184.x |
joplin
|
- | 1.2.1 |