Joplin是Laurent Cozic个人开发者的一款开源的笔记和待办事项应用程序。 Joplin存在输入验证错误漏洞,该漏洞源于Joplin的HTML清理程序中如果指定name属性的值与现有属性的值相同可能导致拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-24028 | 7.8 HIGH | Cross-site Scripting (XSS) in Rich Text Editor allows arbitrary code execution in Joplin |
| CVE-2025-25187 | 7.8 HIGH | Cross-site Scripting in Goto Anything allows arbitrary code execution in Joplin |
No comments yet