Leanote records
9 published records for vendor leanote.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-26158No exploit | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered.leanote · leanote · CWE-79 | Critical9.6 | — | 1.9% | Sep 30, 2020 |
39Monitor | CVE-2020-26157No exploit | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing.leanote · leanote · CWE-79 | Critical9.6 | — | 1.9% | Sep 30, 2020 |
24Monitor | CVE-2021-43721No exploit | Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note.leanote · leanote · CWE-79 | Medium6.1 | — | 1.1% | Mar 28, 2022 |
24Monitor | CVE-2017-1000492No exploit | Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integrationleanote · desktop · CWE-79 | Medium6.1 | — | 1.0% | Jan 2, 2018 |
24Monitor | CVE-2018-18553No exploit | Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.leanote · leanote · CWE-79 | Medium6.1 | — | 0.9% | Oct 21, 2018 |
24Monitor | CVE-2017-1000459No exploit | Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notesleanote · leanote · CWE-79 | Medium6.1 | — | 0.8% | Jan 2, 2018 |
24Monitor | CVE-2019-1010003No exploit | Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).leanote · leanote · CWE-79 | Medium6.1 | — | 0.6% | Jul 11, 2019 |
24Monitor | CVE-2021-4263No exploit | leanote history.js define cross site scriptingleanote · leanote · CWE-79 | Medium6.1 | — | 0.5% | Dec 21, 2022 |
20Monitor | CVE-2024-0849No exploit | Leanote 2.7.0 - Local File Readleanote · desktop · CWE-22 | Medium5.0 | — | 0.2% | Feb 6, 2024 |
- CVE-2020-2615839Monitor
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered.
CriticalCVSS 9.6No exploitEPSS 2%leanote · leanoteSep 30, 2020
- CVE-2020-2615739Monitor
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing.
CriticalCVSS 9.6No exploitEPSS 2%leanote · leanoteSep 30, 2020
- CVE-2021-4372124Monitor
Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note.
MediumCVSS 6.1No exploitEPSS 1%leanote · leanoteMar 28, 2022
- CVE-2017-100049224Monitor
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration
MediumCVSS 6.1No exploitEPSS 1%leanote · desktopJan 2, 2018
- CVE-2018-1855324Monitor
Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.
MediumCVSS 6.1No exploitEPSS 1%leanote · leanoteOct 21, 2018
- CVE-2017-100045924Monitor
Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes
MediumCVSS 6.1No exploitEPSS 1%leanote · leanoteJan 2, 2018
- CVE-2019-101000324Monitor
Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).
MediumCVSS 6.1No exploitEPSS 1%leanote · leanoteJul 11, 2019
- CVE-2021-426324Monitor
leanote history.js define cross site scripting
MediumCVSS 6.1No exploitEPSS 1%leanote · leanoteDec 21, 2022
- CVE-2024-084920Monitor
Leanote 2.7.0 - Local File Read
MediumCVSS 5.0No exploitEPSS 0%leanote · desktopFeb 6, 2024