An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15930.json"