Joplin
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 22 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 21, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Joplin: Unauthenticated account takeover via an attacker-chosen application-authorisation identifier
Joplin Server password reset accepts tokens issued for unrelated purposes
Joplin whiteboard card rendering allows CSS injection into application chrome
Joplin Web Clipper pairing allows cross-origin theft of a permanent API token
Joplin: Stored XSS in public share viewer via javascript: URL bypass in isAcceptedUrl
Joplin: Pending share recipients can write items into shared folders before accepting invitations
Joplin: Stored XSS via inline-served note attachment on published shares
Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its internal server ID
Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash
Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on Windows
Monitor Joplin in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.