Typora
by Typora
CVEs (25)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-7295 | Med | 0.40 | 6.1 | 0.02 | Jan 31, 2019 | typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula. | ||
| CVE-2019-6803 | Med | 0.40 | 6.1 | 0.02 | Jan 25, 2019 | typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar. | ||
| CVE-2023-1003 | Med | 0.34 | 5.3 | 0.00 | Mar 7, 2023 | A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached locally. The exploit has been disclosed… | ||
| CVE-2026-82805 | Med | 0.28 | 4.3 | 0.00 | Aug 31, 2026 | A vulnerability was found in Typora up to 1.13.8/1.14.6. This vulnerability affects unknown code of the component Mermaid Rendering Engine. The manipulation of the argument classDef/style results in cross site scripting. The attack may be launched remotely. The exploit has been… | ||
| CVE-2019-20374 | Cri | 0.00 | 9.6 | 0.02 | Jan 9, 2020 | A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to… |
- risk 0.40cvss 6.1epss 0.02
typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
- risk 0.40cvss 6.1epss 0.02
typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.
- risk 0.34cvss 5.3epss 0.00
A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached locally. The exploit has been disclosed…
- risk 0.28cvss 4.3epss 0.00
A vulnerability was found in Typora up to 1.13.8/1.14.6. This vulnerability affects unknown code of the component Mermaid Rendering Engine. The manipulation of the argument classDef/style results in cross site scripting. The attack may be launched remotely. The exploit has been…
- risk 0.00cvss 9.6epss 0.02
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to…
Page 2 of 2