📦 Joplin

by Joplin Project

🔍 What is Joplin?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-23340

CRITICAL CVSS 9.8 Feb 8, 2022

CVE-2022-23340 is a critical remote code execution vulnerability in Joplin note-taking software. Attackers can execute arbitrary system commands by injecting malicious code into search results, affect...

CVE-2025-27134

HIGH CVSS 8.8 Apr 30, 2025

This privilege escalation vulnerability in Joplin server allows non-admin users to modify their own user accounts via the PATCH /api/users/:id endpoint to set the is_admin field to 1, granting themsel...

CVE-2025-24028

HIGH CVSS 7.8 Feb 7, 2025

This is a cross-site scripting (XSS) vulnerability in Joplin's Rich Text Editor caused by differences between Joplin's HTML sanitizer and browser comment handling. Attackers can execute arbitrary Java...

CVE-2025-25187

HIGH CVSS 7.8 Feb 7, 2025

This vulnerability in Joplin allows attackers to execute arbitrary code on a user's system by injecting malicious JavaScript into note titles. Users who receive notes from untrusted sources and use Ct...

CVE-2024-53268

HIGH CVSS 7.2 Nov 25, 2024

This vulnerability in Joplin note-taking app allows attackers to achieve remote code execution on Windows systems by exploiting unfiltered URI schemes in the openExternal function. All Joplin users on...

CVE-2024-49362

HIGH CVSS 7.7 Nov 14, 2024

Joplin desktop application has a remote code execution vulnerability where clicking malicious links in untrusted notes can execute arbitrary shell commands. This affects all Joplin desktop users who o...

CVE-2023-38506

HIGH CVSS 8.2 Jun 21, 2024

Joplin note-taking application has a cross-site scripting (XSS) vulnerability where pasting untrusted HTML into the rich text editor can execute arbitrary JavaScript. This JavaScript can access NodeJS...

CVE-2023-45673

HIGH CVSS 8.9 Jun 21, 2024

This vulnerability in Joplin note-taking application allows remote code execution when users click on links within PDFs attached to untrusted notes. Attackers can execute arbitrary shell commands on t...