Skip to content
Noroxi

Leanote records

9 published records for vendor leanote.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 19
  3. 20
  4. 22
  5. 24

Bar: total · dark part: CISA KEV.

All records

9 records
  • Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered.

    CriticalCVSS 9.6No exploitEPSS 2%

    leanote · leanoteSep 30, 2020

  • Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing.

    CriticalCVSS 9.6No exploitEPSS 2%

    leanote · leanoteSep 30, 2020

  • Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note.

    MediumCVSS 6.1No exploitEPSS 1%

    leanote · leanoteMar 28, 2022

  • Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration

    MediumCVSS 6.1No exploitEPSS 1%

    leanote · desktopJan 2, 2018

  • Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.

    MediumCVSS 6.1No exploitEPSS 1%

    leanote · leanoteOct 21, 2018

  • Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes

    MediumCVSS 6.1No exploitEPSS 1%

    leanote · leanoteJan 2, 2018

  • Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).

    MediumCVSS 6.1No exploitEPSS 1%

    leanote · leanoteJul 11, 2019

  • CVE-2021-4263
    24Monitor

    leanote history.js define cross site scripting

    MediumCVSS 6.1No exploitEPSS 1%

    leanote · leanoteDec 21, 2022

  • CVE-2024-0849
    20Monitor

    Leanote 2.7.0 - Local File Read

    MediumCVSS 5.0No exploitEPSS 0%

    leanote · desktopFeb 6, 2024