VYPR

Typora

by Typora

CVEs (24)

  • CVE-2019-7295MedJan 31, 2019
    risk 0.40cvss 6.1epss 0.02

    typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.

  • CVE-2019-6803MedJan 25, 2019
    risk 0.40cvss 6.1epss 0.02

    typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.

  • CVE-2023-1003MedMar 7, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached locally. The exploit has been disclosed…

  • CVE-2019-20374CriJan 9, 2020
    risk 0.00cvss 9.6epss 0.02

    A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to…

Page 2 of 2