CVE-2017-9289: Note Project Note

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Bram Korsten Note through 1.2.0 is vulnerable to a reflected XSS in note-source\ui\editor.php (edit parameter).

Affected products

Published 2017-05-29. Last modified 2026-06-17.