Joplinapp

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    2
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-22810

    Joplin: Path traversal in OneNote importer allows overwriting arbitrary files

    Last Modified: Jun 02, 2026
    Published: May 18, 2026

    CVE-2024-49362

    Remote Code Execution on click of <a> Link in markdown preview

    Last Modified: May 07, 2025
    Published: Nov 14, 2024

    CVE-2024-40643

    Joplin has a parsing error leading to Cross-site Scripting (XSS)

    Last Modified: Sep 17, 2024
    Published: Sep 09, 2024

    CVE-2022-40277

    Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existing links in the markdown file before passing them to the 'shell.openExternal' function.

    Last Modified: May 20, 2025
    Published: Sep 30, 2022

    CVE-2022-35131

    Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.

    Last Modified: Nov 21, 2024
    Published: Jul 25, 2022
    Items Per Page
    Joplinapp Vulnerabilities & Security CVEs | CVE-DB