CVE-2021-47963
Anote 1.0 Persistent Cross-Site Scripting Leading to Code Execution
Vexday Risk Score
33Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 5.1EPSS 0.5%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
15 May 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code by injecting malicious payloads into markdown files stored within the application. Attackers can craft malicious markdown files with embedded JavaScript that executes system commands when opened, enabling remote code execution on the victim's computer.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
AnotherNote · Anotepublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/49836unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →