CVE-2021-47844

MEDIUM

Xmind 2020 - Stored Cross-Site Scripting via Malicious Mind Mapping File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47844. PoCs published by TaurusOmar.

AI-analyzed exploit summary This exploit demonstrates an XSS vulnerability in Xmind 2020 that can be leveraged to achieve remote code execution (RCE) via malicious payloads embedded in mind map files. The payloads are encoded to bypass basic filters and execute arbitrary commands when the victim interacts with the file.

Description

Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind mapping files or custom headers. Attackers can craft malicious files with embedded JavaScript that execute system commands when opened, enabling remote code execution through mouse interactions or file opening.

Exploits (1)

exploitdb WORKING POC
by TaurusOmar · javascriptwebappsmultiple
https://www.exploit-db.com/exploits/49827

This exploit demonstrates an XSS vulnerability in Xmind 2020 that can be leveraged to achieve remote code execution (RCE) via malicious payloads embedded in mind map files. The payloads are encoded to bypass basic filters and execute arbitrary commands when the victim interacts with the file.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Xmind 2020
No auth needed
Prerequisites: Victim must open a malicious Xmind file · Victim interaction (mouse movement or click)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/49827
Various Sources product
https://www.xmind.net/
Various Sources exploit
https://imgur.com/a/t96Nxo5

Scores

CVSS v3 6.1
EPSS 0.0003
EPSS Percentile 7.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
Xmind/Xmind 2020
Published Jan 16, 2026
Tracked Since Feb 18, 2026