Vnotex
Products
1- 5 CVEs
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-39904 | Hig | 0.50 | 8.8 | 0.01 | Jul 11, 2024 | VNote is a note-taking platform. Prior to 3.18.1, a code execution vulnerability existed in VNote, which allowed an attacker to execute arbitrary programs on the victim's system. A crafted URI can be used in a note to perform this attack using file:/// as a link. For example,… | ||
| CVE-2019-8419 | Med | 0.40 | 6.1 | 0.01 | Feb 17, 2019 | VNote 2.2 has XSS via a new text note. | ||
| CVE-2023-5701 | Med | 0.28 | 4.3 | 0.01 | Oct 23, 2023 | A vulnerability has been found in vnotex vnote up to 3.17.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Markdown File Handler. The manipulation with the input Click… | ||
| CVE-2026-15505 | Low | 0.00 | 3.5 | 0.00 | Jul 12, 2026 | A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra/web/js/markdownit.js of the component YAML Frontmatter. This manipulation of the argument p_metaData causes cross site scripting. The attack may be initiated… | ||
| CVE-2024-41662 | Hig | 0.00 | 8.6 | 0.02 | Jul 24, 2024 | VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown rendering functionality of versions 3.18.1 and prior of the VNote note-taking application. This vulnerability allows the injection and execution of arbitrary… |
- risk 0.50cvss 8.8epss 0.01
VNote is a note-taking platform. Prior to 3.18.1, a code execution vulnerability existed in VNote, which allowed an attacker to execute arbitrary programs on the victim's system. A crafted URI can be used in a note to perform this attack using file:/// as a link. For example,…
- risk 0.40cvss 6.1epss 0.01
VNote 2.2 has XSS via a new text note.
- risk 0.28cvss 4.3epss 0.01
A vulnerability has been found in vnotex vnote up to 3.17.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Markdown File Handler. The manipulation with the input Click…
- risk 0.00cvss 3.5epss 0.00
A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra/web/js/markdownit.js of the component YAML Frontmatter. This manipulation of the argument p_metaData causes cross site scripting. The attack may be initiated…
- risk 0.00cvss 8.6epss 0.02
VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown rendering functionality of versions 3.18.1 and prior of the VNote note-taking application. This vulnerability allows the injection and execution of arbitrary…