Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note. Read more