Vulnerabilities (CVE)

Filtered by vendor Joplin Project Subscribe
Total 21 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-40643 1 Joplin Project 1 Joplin 2024-09-17 N/A 9.6 CRITICAL
Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.