| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-27134 | Privilege escalation in Joplin server via user patch endpoint | laurent22 | joplin | High | 8.8 | 2025-04-30 14:55:10 | Deep Dive |
| CVE-2025-27409 | Joplin Server Vulnerable to Path Traversal | laurent22 | joplin | High | 7.5 | 2025-04-30 14:55:08 | Deep Dive |
| CVE-2025-25187 | Cross-site Scripting in Goto Anything allows arbitrary code execution in Joplin | laurent22 | joplin | High | 7.8 | 2025-02-07 22:38:20 | Deep Dive |
| CVE-2025-24028 | Cross-site Scripting (XSS) in Rich Text Editor allows arbitrary code execution in Joplin | laurent22 | joplin | High | 7.8 | 2025-02-07 22:23:07 | Deep Dive |
| CVE-2024-55630 | DOM Clobbering leads to temporary DOS in the note viewer in Joplin | laurent22 | joplin | Low | 3.3 | 2025-02-07 22:23:04 | Deep Dive |
| CVE-2024-53268 | Lack of validation on openExternal allows 1 click remote code execution in joplin | laurent22 | joplin | High | 7.2 | 2024-11-25 19:22:17 | Deep Dive |
| CVE-2024-49362 | Remote Code Execution on click of <a> Link in markdown preview | laurent22 | joplin | High | 7.7 | 2024-11-14 17:37:10 | Deep Dive |
| CVE-2024-40643 | Joplin has a parsing error leading to Cross-site Scripting (XSS) | laurent22 | joplin | Critical | 9.6 | 2024-09-09 14:28:21 | Deep Dive |
| CVE-2023-37898 | Safe mode Cross-site Scripting (XSS) vulnerability in Joplin | laurent22 | joplin | High | 8.2 | 2024-06-21 19:45:20 | Deep Dive |
| CVE-2023-38506 | Cross-site Scripting (XSS) when pasting HTML into the rich text editor in Joplin | laurent22 | joplin | High | 8.2 | 2024-06-21 19:43:24 | Deep Dive |
| CVE-2023-39517 | Cross site scripting (XSS) when clicking on an untrusted `<map>` link in Joplin | laurent22 | joplin | High | 8.2 | 2024-06-21 19:41:49 | Deep Dive |
| CVE-2023-45673 | Arbitrary code execution on click of PDF links in Joplin | laurent22 | joplin | High | 8.9 | 2024-06-21 19:38:23 | Deep Dive |
| CVE-2022-40277 | Joplin 输入验证错误漏洞 | - | Joplin | 高危 | - | 2022-09-30 16:20:59 | Deep Dive |
| CVE-2021-23431 | Cross-site Request Forgery (CSRF) | - | joplin | Medium | 5.4 | 2021-08-24 07:45:19 | Deep Dive |