VendorsJoplin Projectjoplinall versions
Vulnerabilities

Joplin Project Joplin

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2022-23340
Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.
Published 2022-02-08 · Modified
9.8EPSS 0.015
CVE-2024-49362
Remote Code Execution on click of <a> Link in markdown preview
Published 2024-11-14 · Analyzed
9.6EPSS 0.010
CVE-2024-40643
Joplin has a parsing error leading to Cross-site Scripting (XSS)
Published 2024-09-09 · Analyzed
9.6EPSS 0.008
CVE-2025-24028
Cross-site Scripting (XSS) in Rich Text Editor allows arbitrary code execution in Joplin
Published 2025-02-07 · Analyzed
9.6EPSS 0.005
CVE-2023-45673
Arbitrary code execution on click of PDF links in Joplin
Published 2024-06-21 · Analyzed
9.0EPSS 0.010
CVE-2025-27134
Privilege escalation in Joplin server via user patch endpoint
Published 2025-04-30 · Analyzed
8.8EPSS 0.021
CVE-2024-53268
Lack of validation on openExternal allows 1 click remote code execution in joplin
Published 2024-11-25 · Analyzed
8.8EPSS 0.007
CVE-2023-39517
Cross site scripting (XSS) when clicking on an untrusted `<map>` link in Joplin
Published 2024-06-21 · Modified
8.2EPSS 0.005
CVE-2023-37898
Safe mode Cross-site Scripting (XSS) vulnerability in Joplin
Published 2024-06-21 · Analyzed
8.2EPSS 0.004
CVE-2023-38506
Cross-site Scripting (XSS) when pasting HTML into the rich text editor in Joplin
Published 2024-06-21 · Analyzed
8.2EPSS 0.004
CVE-2025-25187
Cross-site Scripting in Goto Anything allows arbitrary code execution in Joplin
Published 2025-02-07 · Analyzed
7.8EPSS 0.005
CVE-2025-27409
Joplin Server Vulnerable to Path Traversal
Published 2025-04-30 · Analyzed
7.5EPSS 0.006
CVE-2020-15930
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
Published 2020-09-24 · Modified
6.11 PoCEPSS 0.044
CVE-2020-28249
Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.
Published 2020-11-06 · Modified
6.11 PoCEPSS 0.031
CVE-2018-1000534
Joplin version prior to 1.0.90 contains a XSS evolving into code execution due to enabled nodeIntegration for that particular BrowserWindow instance where XSS was identified from vulnerability in Note content field - information on the fix can be found here https://github.com/laurent22/joplin/commit/494e235e18659574f836f84fcf9f4d4fcdcfcf89 that can result in executing unauthorized code within the rights in which the application is running. This attack appear to be exploitable via Victim synchronizing notes from the cloud services or other note-keeping services which contain malicious code. This vulnerability appears to have been fixed in 1.0.90 and later.
Published 2018-06-26 · Modified
6.1EPSS 0.015
CVE-2021-37916
Joplin before 2.0.9 allows XSS via button and form in the note body.
Published 2021-08-02 · Modified
6.1EPSS 0.007
CVE-2023-37298
Joplin before 2.11.5 allows XSS via a USE element in an SVG document.
Published 2023-06-30 · Modified
6.1EPSS 0.006
CVE-2023-37299
Joplin before 2.11.5 allows XSS via an AREA element of an image map.
Published 2023-06-30 · Modified
6.1EPSS 0.006
CVE-2022-45598
Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper santization.
Published 2023-01-31 · Modified
6.1EPSS 0.005
CVE-2024-55630
DOM Clobbering leads to temporary DOS in the note viewer in Joplin
Published 2025-02-07 · Analyzed
5.5EPSS 0.003
CVE-2020-9038
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
Published 2020-02-17 · Modified
5.41 PoCEPSS 0.036
CVE-2021-33295
Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.
Published 2022-06-16 · Modified
5.4EPSS 0.009