« Volver al listado

Trilium

Trilium: vulnerabilidades y CVE

Trilium tiene 6 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses6
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-77438Alta (7.5)0.41%—27 ago 2026
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls,…
CVE-2026-53580Alta (8.1)0.48%—27 ago 2026
Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-download feature accepts file:// URLs in a note's img tags and reads the referenced local file with no…
CVE-2026-53579Crítica (9.3)0.30%—27 ago 2026
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the book note type, whose…
CVE-2026-53578Crítica (9.3)0.30%—27 ago 2026
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap note type, whose…
CVE-2026-48996Crítica (9.3)0.30%—27 ago 2026
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter does not sanitize note titles, and the GeoMap note view interpolates a marker…
CVE-2026-47727Alta (8.6)0.73%—27 ago 2026
Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the default-on "Safe import" filter fails to neutralize the shareTemplate relation because that relation is not marked as…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript3
  2. T1189 Drive-by Compromise3
  3. T1005 Data from Local System2
  4. T1059 Command and Scripting Interpreter1
  5. T1190 Exploit Public-Facing Application1
  6. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.