VYPR

Flatnotes

by Flatnotes

CVEs (2)

  • CVE-2026-50873CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.00

    An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.

  • CVE-2024-54730HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.