Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

TriliumNext — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting TriliumNext. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities affecting products and services developed by the vendor TriliumNext. It compiles reported security flaws, including unauthorized access, data exposure, and remote code execution risks, documented within the most recent two-year reporting period. Readers can utilize this resource to track the vendor's published security advisories, analyze the frequency of specific weakness classes such as injection or broken authentication, and review the cumulative vulnerability history of TriliumNext software components. The data provides a structured overview for security teams to assess risk trends and identify recurring patterns in the vendor's release cycle. By examining the aggregated entries, stakeholders can better understand the evolution of TriliumNext's security posture and the types of defects that have historically required remediation. This collection serves as a factual reference for due diligence and risk assessment purposes, allowing users to compare current findings against past disclosures without navigating through disparate individual reports. The information presented here is derived from public security advisories and standardized vulnerability databases, offering a consolidated view of the security landscape specific to this manufacturer's offerings.

Top products by TriliumNext: Trilium
CVE ID Title CVSS Severity Published
CVE-2026-77438 Trilium unauthenticated share-search discloses password-protected and hidden shared notes — Trilium CWE-200 7.5 High 2026-08-27
CVE-2026-53580 Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature — Trilium CWE-73 8.1 High 2026-08-27
CVE-2026-53579 Trilium: Note Import to RCE via Book Note — Trilium CWE-79 9.3 Critical 2026-08-27
CVE-2026-53578 Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml — Trilium CWE-79 9.3 Critical 2026-08-27
CVE-2026-48996 Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client — Trilium CWE-79 9.3 Critical 2026-08-27
CVE-2026-47727 Trilium: RCE via `shareTemplate` relation missing `isDangerous` flag — Safe import bypass leading to EJS SSTI (Incomplete Fix of CVE-2026-45668) — Trilium CWE-94 8.6 High 2026-08-27
CVE-2026-45733 Trilium: Stored XSS in note icon rendering leads to Remote Code Execution in Electron desktop app — Trilium CWE-79 8.3 High 2026-08-18
CVE-2026-45668 Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled) — Trilium CWE-22 - - 2026-05-29
CVE-2026-39311 Trilium Notes: Stored XSS Leads to Unauthorized Remote Code Execution (RCE) via Unsanitized SVG Attachments — Trilium CWE-79 6.8 Medium 2026-05-20
CVE-2026-39310 Trilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) Builds — Trilium CWE-284 8.6 High 2026-05-20
CVE-2026-39309 Trilium Notes: macOS TCC Bypass via Prompt Spoofing — Trilium CWE-451 5.5 Medium 2026-05-19
CVE-2026-35593 Trilium Notes has Local File Inclusion via upload modified file API endpoint — Trilium CWE-22 6.8 Medium 2026-05-19
CVE-2025-68621 Trilium Notes has a Timing Attack Vulnerability in /api/login/sync — Trilium CWE-208 7.4 High 2026-02-06
CVE-2025-53544 Trilium Notes is Vulnerable to Brute-force Protection Bypass via Initial Sync Seed Retrieval — Trilium CWE-307 7.5 High 2025-08-05

This page lists every published CVE security advisory associated with TriliumNext. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.