Home/Product/joplin project joplin
Product

joplin project joplin

26 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-22810
< 3.5.7
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7
8.2HIGH
CVE-2025-27409
< 3.3.3
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks
7.5HIGH
CVE-2025-27134
< 3.3.3
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks
8.8HIGH
CVE-2025-25187
< 3.1.24
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks
7.8HIGH
CVE-2025-24028
< 3.2.12
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks
7.8HIGH
CVE-2024-55630
< 3.2.8
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks
3.3LOW
CVE-2024-53268
< 3.0.3
Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In af
7.2HIGH
CVE-2024-49362
< 3.1
Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code exec
7.7HIGH
CVE-2024-40643
< 3.0.15
Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non lett
9.6CRITICAL
CVE-2023-45673
< 2.13.3
Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions
8.9HIGH
CVE-2023-39517
< 2.12.8
Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions a
8.2HIGH
CVE-2023-38506
< 2.12.10
Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows pasting untrust
8.2HIGH
CVE-2023-37898
< 2.12.9
Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an untrusted no
8.2HIGH
CVE-2023-37299
< 2.11.5
Joplin before 2.11.5 allows XSS via an AREA element of an image map.
6.1MEDIUM
CVE-2023-37298
< 2.11.5
Joplin before 2.11.5 allows XSS via a USE element in an SVG document.
6.1MEDIUM
CVE-2022-45598
< 2.9.17
Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper san
6.1MEDIUM
CVE-2022-40277
all versions
Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malic
7.8HIGH
CVE-2022-35131
all versions
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
9.0CRITICAL
CVE-2021-33295
< 1.8.5
Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to impro
5.4MEDIUM
CVE-2022-23340
all versions
Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.
9.8CRITICAL
CVE-2021-23431
< 2.3.2
The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.
5.4MEDIUM
CVE-2021-37916
< 2.0.9
Joplin before 2.0.9 allows XSS via button and form in the note body.
6.1MEDIUM
CVE-2020-28249
all versions
Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.
6.1MEDIUM
CVE-2020-15930
>= 1.0.190 and <= 1.0.245
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
6.1MEDIUM
CVE-2020-9038
<= 1.0.184
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
5.4MEDIUM
CVE-2018-1000534
< 1.0.90
Joplin version prior to 1.0.90 contains a XSS evolving into code execution due to enabled nodeIntegration for that particular Brow
6.1MEDIUM
threatengine.sh