« Volver al listado

Joplin Project

Joplin Project Joplin: vulnerabilidades y CVE

Joplin Project Joplin tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE22
Últimos 12 meses0
Críticas5
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-27409Alta (7.5)0.65%—30 abr 2025
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, path traversal is possible in Joplin Server if static file path…
CVE-2025-27134Alta (8.8)2.2%—30 abr 2025
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a privilege escalation vulnerability exists in the Joplin…
CVE-2025-25187Media (5.4)0.48%—7 feb 2025
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by adding note titles to the document using React's…
CVE-2025-24028Crítica (9.6)0.52%—7 feb 2025
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences between how Joplin's HTML sanitizer handles…
CVE-2024-55630Media (5.5)0.33%—7 feb 2025
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set…
CVE-2024-53268Alta (8.8)0.74%—25 nov 2024
Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions attackers are able to abuse the fact that openExternal is used without…
CVE-2024-49362Crítica (9.6)1.0%—14 nov 2024
Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The issue arises…
CVE-2024-40643Crítica (9.6)0.79%—9 sept 2024
Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting…
CVE-2023-45673Crítica (9)1.0%—21 jun 2024
Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions allows clicking on a link in a PDF in an untrusted note to execute arbitrary shell…
CVE-2023-39517Media (5.4)0.48%—21 jun 2024
Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on an untrusted image link to execute arbitrary shell commands. The HTML…
CVE-2023-38506Media (5.4)0.42%—21 jun 2024
Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows pasting untrusted data into the rich text editor to execute arbitrary code. HTML pasted into the rich…
CVE-2023-37898Media (5.4)0.43%—21 jun 2024
Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an untrusted note opened in safe mode to execute arbitrary code. `packages/renderer/MarkupToHtml.ts`…
CVE-2023-37299Media (6.1)0.57%—30 jun 2023
Joplin before 2.11.5 allows XSS via an AREA element of an image map.
CVE-2023-37298Media (6.1)0.57%—30 jun 2023
Joplin before 2.11.5 allows XSS via a USE element in an SVG document.
CVE-2022-45598Media (6.1)0.45%—31 ene 2023
Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper santization.
CVE-2021-33295Media (5.4)0.85%—16 jun 2022
Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.
CVE-2022-23340Crítica (9.8)1.5%—8 feb 2022
Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.
CVE-2021-37916Media (6.1)0.73%—3 ago 2021
Joplin before 2.0.9 allows XSS via button and form in the note body.
CVE-2020-28249Media (6.1)3.1%—6 nov 2020
Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.
CVE-2020-15930Media (6.1)4.4%—24 sept 2020
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
CVE-2020-9038Media (5.4)3.6%—17 feb 2020
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
CVE-2018-1000534Media (6.1)1.5%—26 jun 2018
Joplin version prior to 1.0.90 contains a XSS evolving into code execution due to enabled nodeIntegration for that particular BrowserWindow instance where XSS was identified from vulnerability in Note content field -…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1189 Drive-by Compromise2
  3. T1005 Data from Local System1
  4. T1059.007 JavaScript1
  5. T1068 Exploitation for Privilege Escalation1
  6. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.