Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

laurent22 — Vulnerabilities & Security Advisories 30

Browse all 30 CVE security advisories affecting laurent22. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Laurent22 primarily develops web applications and APIs, with a core focus on e-commerce platforms. Historically, vulnerabilities attributed to this entity include remote code execution, cross-site scripting (XSS), and privilege escalation, often stemming from input validation flaws and insecure authentication mechanisms. Security assessments reveal consistent patterns in insecure direct object references and server-side request forgery. While no major public incidents have been documented, the cumulative 12 CVEs highlight persistent security challenges in their codebase, particularly in handling user-supplied data and access control implementations.

Top products by laurent22: joplin
CVE ID Title CVSS Severity Published
CVE-2026-105786 Joplin: Unauthenticated account takeover via an attacker-chosen application-authorisation identifier — joplin CWE-306 8.5 High 2026-10-05
CVE-2026-105785 Joplin Server password reset accepts tokens issued for unrelated purposes — joplin CWE-620 4.8 Medium 2026-10-05
CVE-2026-105784 Joplin whiteboard card rendering allows CSS injection into application chrome — joplin CWE-79 4.6 Medium 2026-10-05
CVE-2026-105783 Joplin Web Clipper pairing allows cross-origin theft of a permanent API token — joplin CWE-346 8.0 High 2026-10-05
CVE-2026-46650 Joplin: Stored XSS in public share viewer via javascript: URL bypass in isAcceptedUrl — joplin CWE-79 4.4 Medium 2026-09-21
CVE-2026-59815 Joplin: Pending share recipients can write items into shared folders before accepting invitations — joplin CWE-863 4.3 Medium 2026-09-21
CVE-2026-55210 Joplin: SAML SSO account takeover via email-based account linking (missing is_external check in ssoLogin) — joplin CWE-290 7.4 High 2026-09-21
CVE-2026-59814 Joplin: Stored XSS via inline-served note attachment on published shares — joplin CWE-79 7.6 High 2026-09-21
CVE-2026-55105 Joplin: Fountain embeds allow arbitrary script execution in published notes and the note viewer — joplin CWE-79 7.7 High 2026-09-21
CVE-2026-46649 Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint — joplin CWE-307 9.1 Critical 2026-09-21
CVE-2026-55179 Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its internal server ID — joplin CWE-639 6.5 Medium 2026-09-21
CVE-2026-59816 Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash — joplin CWE-22 4.3 Medium 2026-09-21
CVE-2026-49449 Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on Windows — joplin CWE-200 2.5 Low 2026-09-21
CVE-2026-49453 Joplin: Path traversal in resource sync — silent arbitrary file write outside the resource directory — joplin CWE-20 7.0 High 2026-09-21
CVE-2026-49450 Joplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherName — joplin CWE-345 7.1 High 2026-09-21
CVE-2026-34600 Joplin Server delta API returns note content after share access is revoked — joplin CWE-281 5.7 Medium 2026-05-19
CVE-2025-57798 Joplin has Denial of Service (DoS) via Uncontrolled Resource Allocation through Title Input — joplin CWE-770 5.5 Medium 2026-05-19
CVE-2026-22810 Joplin: Path traversal in OneNote importer allows overwriting arbitrary files — joplin CWE-24 8.2 High 2026-05-18
CVE-2025-27134 Privilege escalation in Joplin server via user patch endpoint — joplin CWE-284 8.8 High 2025-04-30
CVE-2025-27409 Joplin Server Vulnerable to Path Traversal — joplin CWE-22 7.5 High 2025-04-30
CVE-2025-25187 Cross-site Scripting in Goto Anything allows arbitrary code execution in Joplin — joplin CWE-79 7.8 High 2025-02-07
CVE-2025-24028 Cross-site Scripting (XSS) in Rich Text Editor allows arbitrary code execution in Joplin — joplin CWE-79 7.8 High 2025-02-07
CVE-2024-55630 DOM Clobbering leads to temporary DOS in the note viewer in Joplin — joplin CWE-20 3.3 Low 2025-02-07
CVE-2024-53268 Lack of validation on openExternal allows 1 click remote code execution in joplin — joplin CWE-94 7.3 High 2024-11-25
CVE-2024-49362 Remote Code Execution on click of <a> Link in markdown preview — joplin CWE-94 7.7 High 2024-11-14
CVE-2024-40643 Joplin has a parsing error leading to Cross-site Scripting (XSS) — joplin CWE-79 9.7 Critical 2024-09-09
CVE-2023-37898 Safe mode Cross-site Scripting (XSS) vulnerability in Joplin — joplin CWE-79 8.2 High 2024-06-21
CVE-2023-38506 Cross-site Scripting (XSS) when pasting HTML into the rich text editor in Joplin — joplin CWE-79 8.2 High 2024-06-21
CVE-2023-39517 Cross site scripting (XSS) when clicking on an untrusted `<map>` link in Joplin — joplin CWE-79 8.2 High 2024-06-21
CVE-2023-45673 Arbitrary code execution on click of PDF links in Joplin — joplin CWE-94 8.9 High 2024-06-21

This page lists every published CVE security advisory associated with laurent22. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.