Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Trilium — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Trilium, with AI-generated Chinese analysis, references, and POCs.

This page aggregates recorded software vulnerabilities associated with the vendor Trilium and the Trilium knowledge base application. It collects security advisories that document weaknesses such as remote code execution, cross-site scripting, and denial-of-service issues, covering disclosures published from 2019 through the present. Readers can use this aggregation to track the vendor's historical security posture, analyze the recurrence of specific weakness classes, and review the complete vulnerability history for the Trilium product line. The entries are indexed by weakness type and release version, allowing analysts to correlate individual defects with the broader pattern of flaws observed over several years of development. No specific CVE identifiers are listed; instead, the focus remains on the collective impact and evolution of these vulnerabilities.

Vendor: TriliumNext

CVE ID Title CVSS Severity Published
CVE-2026-77438 Trilium unauthenticated share-search discloses password-protected and hidden shared notes CWE-200 7.5 High 2026-08-27
CVE-2026-53580 Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature CWE-73 8.1 High 2026-08-27
CVE-2026-53579 Trilium: Note Import to RCE via Book Note CWE-79 9.3 Critical 2026-08-27
CVE-2026-53578 Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml CWE-79 9.3 Critical 2026-08-27
CVE-2026-48996 Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client CWE-79 9.3 Critical 2026-08-27
CVE-2026-47727 Trilium: RCE via `shareTemplate` relation missing `isDangerous` flag — Safe import bypass leading to EJS SSTI (Incomplete Fix of CVE-2026-45668) CWE-94 8.6 High 2026-08-27
CVE-2026-45733 Trilium: Stored XSS in note icon rendering leads to Remote Code Execution in Electron desktop app CWE-79 8.3 High 2026-08-18
CVE-2026-45668 Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled) CWE-22 - - 2026-05-29
CVE-2026-39311 Trilium Notes: Stored XSS Leads to Unauthorized Remote Code Execution (RCE) via Unsanitized SVG Attachments CWE-79 6.8 Medium 2026-05-20
CVE-2026-39310 Trilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) Builds CWE-284 8.6 High 2026-05-20
CVE-2026-39309 Trilium Notes: macOS TCC Bypass via Prompt Spoofing CWE-451 5.5 Medium 2026-05-19
CVE-2026-35593 Trilium Notes has Local File Inclusion via upload modified file API endpoint CWE-22 6.8 Medium 2026-05-19
CVE-2025-68621 Trilium Notes has a Timing Attack Vulnerability in /api/login/sync CWE-208 7.4 High 2026-02-06
CVE-2025-53544 Trilium Notes is Vulnerable to Brute-force Protection Bypass via Initial Sync Seed Retrieval CWE-307 7.5 High 2025-08-05

All 14 known CVE vulnerabilities affecting Trilium with full Chinese analysis, references, and POCs where available.