CVE-2017-9289: Note Project Note
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Bram Korsten Note through 1.2.0 is vulnerable to a reflected XSS in note-source\ui\editor.php (edit parameter).
Affected products
- Note Project Note: up to and including 1.2.0
Published 2017-05-29. Last modified 2026-06-17.