Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 301 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | — | — | JoplinAI | 5/10/2026 | 5/10/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, packages/server/src/models/ApplicationModel.ts accepts a caller-chosen application authorization identifier, applications/:id/confirm binds that identifier to a logged-in user through a generic… | |
| Aplazada | Media (4.8) | — | — | Joplin ServerAI | 5/10/2026 | 5/10/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts… | |
| Aplazada | Media (4.6) | — | — | JoplinAI | 5/10/2026 | 5/10/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas fence causes the whiteboard text and file-node components in packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/TextNode.tsx and… | |
| Aplazada | Alta (8) | — | — | JoplinAI | 5/10/2026 | 5/10/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, when Joplin Desktop is running with the opt-in Web Clipper server enabled, the server in packages/lib/ClipperServer.ts sends Access-Control-Allow-Origin: * and allows an arbitrary website to call… | |
| Aplazada | Media (4.3) | 0.23% | — | Joplin ServerAI | 21/9/2026 | 24/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to items with a share ID when any share_users row exists for the caller, without requiring ShareUserStatus.Accepted. A low-privileged… | |
| Aplazada | Alta (7.6) | 0.35% | — | Joplin ServerAI | 21/9/2026 | 23/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's GET /shares/:id?resource_id= route serves a resource with the attacker-controlled mime value and omits Content-Disposition when the resource title is empty. A low-privileged user… | |
| Aplazada | Alta (7.4) | 0.48% | — | Joplin ServerAI | 21/9/2026 | 23/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's UserModel.ssoLogin() returns an existing account matched by an IdP-asserted email without checking the account's is_external flag. In deployments using mixed local and SAML… | |
| Aplazada | Media (4.4) | 0.28% | — | JoplinAI | 21/9/2026 | 29/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular expression for internal resource URLs, allowing a javascript: URL containing a matching 32-character path fragment to… | |
| Aplazada | Media (4.3) | 0.36% | — | Joplin ServerAI | 21/9/2026 | 23/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, the GET /api/transcribe/:id and POST /api/transcribe/:id handlers in packages/server/src/routes/api/transcribe.ts on Joplin Server instances with TRANSCRIBE_ENABLED=true pass the decoded id… | |
| Aplazada | Media (6.5) | 0.26% | — | Joplin ServerAI | 21/9/2026 | 23/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in packages/server/src/routes/index/items.ts loads item content from an attacker-supplied internal server ID without checking whether the signed-in user… | |
| Aplazada | Alta (7.7) | 0.50% | — | JoplinAI | 21/9/2026 | 24/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, packages/renderer/MdToHtml/rules/fountain.ts passes HTML generated by the vendored fountain.js renderer into note output without sanitizing it. A malicious Fountain code block can… | |
| Aplazada | Alta (7) | 0.41% | — | JoplinAI | 21/9/2026 | 23/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource metadata whose id or file_extension contains parent-directory or path-separator characters. BaseItem.unserialize() stores the unvalidated fields,… | |
| Aplazada | Alta (7.1) | 0.18% | — | Joplin DesktopAI | 21/9/2026 | 23/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.yml causes NsisUpdater.verifySignature() to skip comparison of a downloaded… | |
| Aplazada | Baja (2.5) | 0.20% | — | JoplinAI | 21/9/2026 | 28/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust option for note content, allowing a note author to place a \href URL into rendered output without passing Joplin's normal URL… | |
| Aplazada | Crítica (9.1) | 0.50% | — | Joplin ServerAI | 21/9/2026 | 28/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker… | |
| Aplazada | Media (5.7) | 0.36% | — | JoplinAI | 19/5/2026 | 24/7/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic error in the delta API that allows share recipients to download notes that are no longer shared with them, related to but not fully fixed by the prior patch in #14289. In… | |
| Aplazada | Media (5.5) | 0.16% | — | JoplinAI | 19/5/2026 | 24/7/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.14 and prior contain a Denial of Service (DoS) vulnerability in the title input functionality due to a lack of proper length validation. This flaw allows an attacker to cause an Out Of Memory (OOM)… | |
| Analizada | Alta (7.3) | 0.21% | — | Joplinapp JoplinMsiemens One2html | 18/5/2026 | 24/7/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing… | |
| Analizada | Alta (7.5) | 0.65% | — | Joplin Project Joplin | 30/4/2025 | 17/6/2026 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, path traversal is possible in Joplin Server if static file path starts with `css/pluginAssets` or `js/pluginAssets`. The `findLocalFile` function in the `default… | |
| Analizada | Alta (8.8) | 2.2% | — | Joplin Project Joplin | 30/4/2025 | 17/6/2026 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a privilege escalation vulnerability exists in the Joplin server, allowing non-admin users to exploit the API endpoint `PATCH /api/users/:id` to set the `is_admin`… | |
| Analizada | Media (5.4) | 0.48% | — | Joplin Project Joplin | 7/2/2025 | 17/6/2026 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by adding note titles to the document using React's `dangerouslySetInnerHTML`, without first escaping HTML entities. Joplin lacks a Content-Security-Policy… | |
| Analizada | Crítica (9.6) | 0.52% | — | Joplin Project Joplin | 7/2/2025 | 17/6/2026 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences between how Joplin's HTML sanitizer handles comments and how the browser handles comments. This affects both the Rich Text Editor and the… | |
| Analizada | Media (5.5) | 0.33% | — | Joplin Project Joplin | 7/2/2025 | 17/6/2026 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set to the same value as an existing `document` property (e.g. `querySelector`), that property is… | |
| Analizada | Alta (8.8) | 0.74% | — | Joplin Project Joplin | 25/11/2024 | 17/6/2026 | Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions attackers are able to abuse the fact that openExternal is used without any filtering of URI schemes to obtain remote code execution in Windows environments. This issue has… | |
| Analizada | Crítica (9.6) | 1.0% | — | Joplin Project Joplin | 14/11/2024 | 17/6/2026 | Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The issue arises due to insufficient sanitization of <a> tag attributes introduced by the Mermaid. This vulnerability… |