Products: 2
    Vulnerabilities: 9
    Known Exploited: 0
    2
    Critical Level Threats
    0
    High Level Threats
    6
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-0849

    Leanote 2.7.0 - Local File Read

    Last Modified: Apr 20, 2026
    Published: Feb 07, 2024

    CVE-2021-4263

    leanote history.js define cross site scripting

    Last Modified: Apr 14, 2025
    Published: Dec 21, 2022

    CVE-2021-43721

    Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : <video src=x onerror=(function(){require('child_process').exec('calc');})();>

    Last Modified: Nov 21, 2024
    Published: Mar 28, 2022

    CVE-2020-26157

    Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration.

    Last Modified: Nov 21, 2024
    Published: Sep 30, 2020

    CVE-2020-26158

    Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration.

    Last Modified: Nov 21, 2024
    Published: Sep 30, 2020
    Items Per Page
    Leanote Vulnerabilities & Security CVEs | CVE-DB