Joplin Project
Joplin Project Joplin: vulnerabilidades y CVE
Joplin Project Joplin tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-27409 | Alta (7.5) | 0.65% | — | 30 abr 2025 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, path traversal is possible in Joplin Server if static file path… |
| CVE-2025-27134 | Alta (8.8) | 2.2% | — | 30 abr 2025 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a privilege escalation vulnerability exists in the Joplin… |
| CVE-2025-25187 | Media (5.4) | 0.48% | — | 7 feb 2025 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by adding note titles to the document using React's… |
| CVE-2025-24028 | Crítica (9.6) | 0.52% | — | 7 feb 2025 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences between how Joplin's HTML sanitizer handles… |
| CVE-2024-55630 | Media (5.5) | 0.33% | — | 7 feb 2025 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set… |
| CVE-2024-53268 | Alta (8.8) | 0.74% | — | 25 nov 2024 | Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions attackers are able to abuse the fact that openExternal is used without… |
| CVE-2024-49362 | Crítica (9.6) | 1.0% | — | 14 nov 2024 | Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The issue arises… |
| CVE-2024-40643 | Crítica (9.6) | 0.79% | — | 9 sept 2024 | Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting… |
| CVE-2023-45673 | Crítica (9) | 1.0% | — | 21 jun 2024 | Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions allows clicking on a link in a PDF in an untrusted note to execute arbitrary shell… |
| CVE-2023-39517 | Media (5.4) | 0.48% | — | 21 jun 2024 | Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on an untrusted image link to execute arbitrary shell commands. The HTML… |
| CVE-2023-38506 | Media (5.4) | 0.42% | — | 21 jun 2024 | Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows pasting untrusted data into the rich text editor to execute arbitrary code. HTML pasted into the rich… |
| CVE-2023-37898 | Media (5.4) | 0.43% | — | 21 jun 2024 | Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an untrusted note opened in safe mode to execute arbitrary code. `packages/renderer/MarkupToHtml.ts`… |
| CVE-2023-37299 | Media (6.1) | 0.57% | — | 30 jun 2023 | Joplin before 2.11.5 allows XSS via an AREA element of an image map. |
| CVE-2023-37298 | Media (6.1) | 0.57% | — | 30 jun 2023 | Joplin before 2.11.5 allows XSS via a USE element in an SVG document. |
| CVE-2022-45598 | Media (6.1) | 0.45% | — | 31 ene 2023 | Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper santization. |
| CVE-2021-33295 | Media (5.4) | 0.85% | — | 16 jun 2022 | Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html. |
| CVE-2022-23340 | Crítica (9.8) | 1.5% | — | 8 feb 2022 | Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results. |
| CVE-2021-37916 | Media (6.1) | 0.73% | — | 3 ago 2021 | Joplin before 2.0.9 allows XSS via button and form in the note body. |
| CVE-2020-28249 | Media (6.1) | 3.1% | — | 6 nov 2020 | Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note. |
| CVE-2020-15930 | Media (6.1) | 4.4% | — | 24 sept 2020 | An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag. |
| CVE-2020-9038 | Media (5.4) | 3.6% | — | 17 feb 2020 | Joplin through 1.0.184 allows Arbitrary File Read via XSS. |
| CVE-2018-1000534 | Media (6.1) | 1.5% | — | 26 jun 2018 | Joplin version prior to 1.0.90 contains a XSS evolving into code execution due to enabled nodeIntegration for that particular BrowserWindow instance where XSS was identified from vulnerability in Note content field -… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.