CVE-2024-40643: Joplin Project Joplin
Critical severity, CVSS 9.6. EPSS: 0.8% chance of exploitation in the next 30 days.
Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.
Affected products
- Joplin Project Joplin: before 3.0.15 (fixed in 3.0.15)
Published 2024-09-09. Last modified 2026-06-17.