8.2

CVSS3.1

CVE-2023-37898 - Safe mode Cross-site Scripting (XSS) vulnerability in Joplin

Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an untrusted note opened in safe mode to execute arbitrary code. `packages/renderer/MarkupToHtml.ts` renders note content in safe mode by surrounding it with <pre> and </pre>, without …

πŸ“… Published: June 21, 2024, 7:45 p.m. πŸ”„ Last Modified: April 11, 2025, 5:19 p.m.

8.2

CVSS3.1

CVE-2023-38506 - Cross-site Scripting (XSS) when pasting HTML into the rich text editor in Joplin

Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows pasting untrusted data into the rich text editor to execute arbitrary code. HTML pasted into the rich text editor is not sanitized (or not sanitized properly). As such, the `onload` at…

πŸ“… Published: June 21, 2024, 7:43 p.m. πŸ”„ Last Modified: April 11, 2025, 3:17 p.m.

8.2

CVSS3.1

CVE-2023-39517 - Cross site scripting (XSS) when clicking on an untrusted `<map>` link in Joplin

Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on an untrusted image link to execute arbitrary shell commands. The HTML sanitizer (`packages/renderer/htmlUtils.ts::sanitizeHtml`) preserves `<map>` `<ar…

πŸ“… Published: June 21, 2024, 7:41 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:15 a.m.

8.9

CVSS3.1

CVE-2023-45673 - Arbitrary code execution on click of PDF links in Joplin

Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions allows clicking on a link in a PDF in an untrusted note to execute arbitrary shell commands. Clicking links in PDFs allows for arbitrary code execution because Joplin de…

πŸ“… Published: June 21, 2024, 7:38 p.m. πŸ”„ Last Modified: April 11, 2025, 3:17 p.m.

0.0

CVE-2024-39306 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-39304. Reason: This candidate is a duplicate of CVE-2024-39304. Notes: All CVE users should reference CVE-2024-39304 instead of this candidate. This CVE was issued to a vulnerability that is dependent on CVE-2024-39304. According t…

πŸ“… Published: June 21, 2024, 6:15 p.m. πŸ”„ Last Modified: Aug. 19, 2024, 2:15 p.m.

5.3

CVSS4.0

CVE-2024-6241 - Pear Admin Boot getDictItems sql injection

A vulnerability was found in Pear Admin Boot up to 2.0.2 and classified as critical. This issue affects the function getDictItems of the file /system/dictData/getDictItems/. The manipulation with the input ,user(),1,1 leads to sql injection. The attack may be initiated remotely. The exploit has bee…

πŸ“… Published: June 21, 2024, 5 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

6.5

CVSS3.1

CVE-2024-35781 - WordPress Word Balloon plugin <= 4.21.1 - Local File Inclusion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YAHMAN Word Balloon allows PHP Local File Inclusion.This issue affects Word Balloon: from n/a through 4.21.1.

πŸ“… Published: June 21, 2024, 4:04 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:20 a.m.

6.5

CVSS3.1

CVE-2024-35778 - WordPress Slideshow SE plugin <= 2.5.17 - Auth. Limited Local File Inclusion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John West Slideshow SE PHP Local File Inclusion.This issue affects Slideshow SE: from n/a through 2.5.17.

πŸ“… Published: June 21, 2024, 4:02 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:20 a.m.

9.1

CVSS3.1

CVE-2024-35767 - WordPress Squeeze plugin <= 1.4 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Code Injection.This issue affects Squeeze: from n/a through 1.4.

πŸ“… Published: June 21, 2024, 4 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:20 a.m.

9.8

CVSS3.1

CVE-2023-38389 - WordPress Jupiter X Core plugin <= 3.3.8 - Unauthenticated Account Takeover vulnerability

Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.

πŸ“… Published: June 21, 2024, 3:58 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:13 a.m.
Total resulsts: 347066
Page 9147 of 34,707
Β« previous page Β» next page
Filters