Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-0849 | Leanote version 2.7.0 allows obtaining arbitrary local files. Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR. NVD description · AI analysis pending | 5.0 | <1% |
| — | ||
| CVE-2021-4263 | A vulnerability, which was classified as problematic, has been found in leanote 2.6.1. A vulnerability, which was classified as problematic, has been found in leanote 2.6.1. This issue affects the function define of the file public/js/plugins/history.js. The manipulation of the argument content leads to cross site scripting. The attack may be initiated remotely. The identifier of the patch is 0f9733c890077942150696dcc6d2b1482b7a0a19. It is recommended to apply a patch to fix this issue. The identifier VDB-216461 was assigned to this vulnerability. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2021-43721 | Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2020-26158 +1 in the same advisory: …26157 | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration. NVD description · AI analysis pending | 9.6 | 2% |
| — | ||
| CVE-2019-1010003 | Leanote prior to version 2.6 is affected by: Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS). NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2018-18553 | Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page. Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2017-1000492 | Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration NVD description · AI analysis pending | 6.1 | 1% |
| — | ||
| CVE-2017-1000459 | Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — |