Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Joplin HIGH 7.5
CVE-2025-27409

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version …

Fix: 3.3.3+
Fix from $1,950 2025-04-30
Joplin HIGH 8.8
CVE-2025-27134

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version …

Fix: 3.3.3+
Fix from $1,950 2025-04-30
Joplin CRITICAL 9.6
CVE-2025-24028

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerabilit…

Fix: 3.2.12+
Fix from $2,300 2025-02-07
Joplin MEDIUM 5.4
CVE-2025-25187

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerabilit…

Fix: 3.1.24+
Fix from $1,600 2025-02-07
Joplin MEDIUM 5.5
CVE-2024-55630

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML san…

Fix: 3.2.8+
Fix from $1,600 2025-02-07
Joplin HIGH 8.8
CVE-2024-53268

Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions att…

Fix: 3.0.3+
Fix from $1,950 2024-11-25
Joplin CRITICAL 9.6
CVE-2024-49362

Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a …

Fix: 3.1+
Fix from $2,300 2024-11-14
Joplin CRITICAL 9.6
CVE-2024-40643

Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will n…

Fix: 3.0.15+
Fix from $2,300 2024-09-09
Joplin CRITICAL 9.0
CVE-2023-45673

Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions allows clicking on …

Fix: 2.13.3+
Fix from $2,300 2024-06-21
Joplin MEDIUM 5.4
CVE-2023-38506

Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows pasting untrusted data into the ri…

Fix: 2.12.10+
Fix from $1,600 2024-06-21
Joplin MEDIUM 5.4
CVE-2023-39517

Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on a…

Fix: 2.12.8+
Fix from $1,600 2024-06-21
Joplin MEDIUM 5.4
CVE-2023-37898

Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an untrusted note opened in safe m…

Fix: 2.12.9+
Fix from $1,600 2024-06-21
Joplin MEDIUM 6.1
CVE-2023-37298

Joplin before 2.11.5 allows XSS via a USE element in an SVG document.

Fix: 2.11.5+
Fix from $1,600 2023-06-30
Joplin MEDIUM 6.1
CVE-2023-37299

Joplin before 2.11.5 allows XSS via an AREA element of an image map.

Fix: 2.11.5+
Fix from $1,600 2023-06-30
Joplin MEDIUM 6.1
CVE-2022-45598

Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper santization.

Fix: 2.9.17+
Fix from $1,600 2023-01-31
Joplin MEDIUM 5.4
CVE-2021-33295

Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of h…

Fix: 1.8.5+
Fix from $1,600 2022-06-16
Joplin CRITICAL 9.8
CVE-2022-23340

Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.

No fix yet
Fix from $2,300 2022-02-08
Joplin MEDIUM 6.1
CVE-2021-37916

Joplin before 2.0.9 allows XSS via button and form in the note body.

Fix: 2.0.9+
Fix from $1,600 2021-08-03
Joplin MEDIUM 6.1
CVE-2020-28249

Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.

No fix yet
Fix from $1,600 2020-11-06
Joplin MEDIUM 6.1
CVE-2020-15930

An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.

Fix: after 1.0.245
Fix from $1,600 2020-09-24
Joplin MEDIUM 5.4
CVE-2020-9038

Joplin through 1.0.184 allows Arbitrary File Read via XSS.

Fix: after 1.0.184
Fix from $1,600 2020-02-17
Joplin MEDIUM 6.1
CVE-2018-1000534

Joplin version prior to 1.0.90 contains a XSS evolving into code execution due to enabled nodeIntegration for that particular BrowserWindow instance …

Fix: 1.0.90+
Fix from $1,600 2018-06-26