← Back

Joplin

joplin

Vendor: Joplinapp • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Joplinapp
Msiemens
2Joplin
One2html
Jun 17, 2026
May 18, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary...Show more
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it's possible for an attacker to create a malicious .one file that includes file names containing ../../, that are then interpreted as part of the target path when extracting attachments from the .one file. This issue has been patched in version 3.5.7.Show less
1Joplinapp
1Joplin
Jun 17, 2026
Sep 30, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly...Show more
Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existing links in the markdown file before passing them to the 'shell.openExternal' function.Show less
1Joplinapp
1Joplin
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
1Joplinapp
1Joplin
Jun 17, 2026
Aug 24, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.