VYPR

Joplin

by Joplin Project

Source repositories

CVEs (22)

  • CVE-2024-55630LowFeb 7, 2025
    risk 0.00cvss 3.3epss 0.00

    Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set to the same value as an existing `document` property (e.g.…

  • CVE-2023-39517HigJun 21, 2024
    risk 0.00cvss 8.2epss 0.00

    Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on an untrusted image link to execute arbitrary shell commands. The HTML sanitizer (`packages/renderer/htmlUtils.ts::sanitizeHtml`)…

Page 2 of 2