Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

joplin — Vulnerabilities & Security Advisories 28

All 28 CVE vulnerabilities found in joplin, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting Joplin, the open-source note-taking application. It compiles advisories related to common weakness classes, including cross-site scripting, path traversal, and deserialization flaws, covering issues reported from 2019 through 2024. Readers can use this index to track the vendor’s published security notices, analyze the prevalence of specific flaw types, and review the chronological vulnerability history of the product. The collection is organized to support rapid reference for security teams and developers maintaining Joplin instances.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-46650 Joplin: Stored XSS in public share viewer via javascript: URL bypass in isAcceptedUrl CWE-79 4.4 Medium 2026-09-21
CVE-2026-59815 Joplin: Pending share recipients can write items into shared folders before accepting invitations CWE-863 4.3 Medium 2026-09-21
CVE-2026-55210 Joplin: SAML SSO account takeover via email-based account linking (missing is_external check in ssoLogin) CWE-290 7.4 High 2026-09-21
CVE-2026-59814 Joplin: Stored XSS via inline-served note attachment on published shares CWE-79 7.6 High 2026-09-21
CVE-2026-55105 Joplin: Fountain embeds allow arbitrary script execution in published notes and the note viewer CWE-79 7.7 High 2026-09-21
CVE-2026-46649 Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint CWE-307 9.1 Critical 2026-09-21
CVE-2026-55179 Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its internal server ID CWE-639 6.5 Medium 2026-09-21
CVE-2026-59816 Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash CWE-22 4.3 Medium 2026-09-21
CVE-2026-49449 Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on Windows CWE-200 2.5 Low 2026-09-21
CVE-2026-49453 Joplin: Path traversal in resource sync — silent arbitrary file write outside the resource directory CWE-20 7.0 High 2026-09-21
CVE-2026-49450 Joplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherName CWE-345 7.1 High 2026-09-21
CVE-2026-34600 Joplin Server delta API returns note content after share access is revoked CWE-281 5.7 Medium 2026-05-19
CVE-2025-57798 Joplin has Denial of Service (DoS) via Uncontrolled Resource Allocation through Title Input CWE-770 5.5 Medium 2026-05-19
CVE-2026-22810 Joplin: Path traversal in OneNote importer allows overwriting arbitrary files CWE-24 8.2 High 2026-05-18
CVE-2025-27134 Privilege escalation in Joplin server via user patch endpoint CWE-284 8.8 High 2025-04-30
CVE-2025-27409 Joplin Server Vulnerable to Path Traversal CWE-22 7.5 High 2025-04-30
CVE-2025-25187 Cross-site Scripting in Goto Anything allows arbitrary code execution in Joplin CWE-79 7.8 High 2025-02-07
CVE-2025-24028 Cross-site Scripting (XSS) in Rich Text Editor allows arbitrary code execution in Joplin CWE-79 7.8 High 2025-02-07
CVE-2024-55630 DOM Clobbering leads to temporary DOS in the note viewer in Joplin CWE-20 3.3 Low 2025-02-07
CVE-2024-53268 Lack of validation on openExternal allows 1 click remote code execution in joplin CWE-94 7.3 High 2024-11-25
CVE-2024-49362 Remote Code Execution on click of <a> Link in markdown preview CWE-94 7.7 High 2024-11-14
CVE-2024-40643 Joplin has a parsing error leading to Cross-site Scripting (XSS) CWE-79 9.7 Critical 2024-09-09
CVE-2023-37898 Safe mode Cross-site Scripting (XSS) vulnerability in Joplin CWE-79 8.2 High 2024-06-21
CVE-2023-38506 Cross-site Scripting (XSS) when pasting HTML into the rich text editor in Joplin CWE-79 8.2 High 2024-06-21
CVE-2023-39517 Cross site scripting (XSS) when clicking on an untrusted `<map>` link in Joplin CWE-79 8.2 High 2024-06-21
CVE-2023-45673 Arbitrary code execution on click of PDF links in Joplin CWE-94 8.9 High 2024-06-21
CVE-2022-40277 Joplin 输入验证错误漏洞 7.8 - 2022-09-30
CVE-2021-23431 Cross-site Request Forgery (CSRF) 5.4 Medium 2021-08-24

All 28 known CVE vulnerabilities affecting joplin with full Chinese analysis, references, and POCs where available.