CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Joplin before 2.11.5 allows XSS via an AREA element of an image map.