Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's GET /shares/:id?resource_id= route serves a resource with the attacker-controlled mime value and omits Content-Disposition
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-46649 | 9.1 CRITICAL | Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable v |
| CVE-2026-55105 | 7.7 HIGH | Joplin: Fountain embeds allow arbitrary script execution in published notes and the note v |
| CVE-2026-55210 | 7.4 HIGH | Joplin: SAML SSO account takeover via email-based account linking (missing is_external che |
| CVE-2026-49450 | 7.1 HIGH | Joplin desktop Windows auto-updater accepts signed installer from any publisher because ap |
| CVE-2026-49453 | 7.0 HIGH | Joplin: Path traversal in resource sync — silent arbitrary file write outside the resource |
| CVE-2026-55179 | 6.5 MEDIUM | Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its int |
| CVE-2026-46650 | 4.4 MEDIUM | Joplin: Stored XSS in public share viewer via javascript: URL bypass in isAcceptedUrl |
| CVE-2026-59816 | 4.3 MEDIUM | Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash |
| CVE-2026-59815 | 4.3 MEDIUM | Joplin: Pending share recipients can write items into shared folders before accepting invi |
| CVE-2026-49449 | 2.5 LOW | Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft |
No comments yet