Typora records
23 published records for vendor typora.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 11
- With a fix record
- 4.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-290 Authentication Bypass by Spoofing1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-2317No exploit | Typora DOM-Based Cross-site Scripting leading to Remote Code Executiontypora · typora · CWE-79 | Critical9.6 | — | 2.4% | Aug 19, 2023 |
39Monitor | CVE-2019-20374No exploit | A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Executiontypora · typora · CWE-79 | Critical9.6 | — | 2.3% | Jan 9, 2020 |
33Monitor | CVE-2019-12137Proof of concept | Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared notetypora · typora · CWE-22 | High7.8 | — | 6.5% | May 16, 2019 |
32Monitor | CVE-2019-12172No exploit | Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstypora · typora · CWE-22 | High7.8 | — | 1.8% | May 17, 2019 |
31Monitor | CVE-2023-1003No exploit | Typora WSH JScript code injectiontypora · typora · CWE-94 | High7.8 | — | 0.4% | Mar 7, 2023 |
29Monitor | CVE-2023-2316No exploit | Typora Local File Disclosuretypora · typora · CWE-22 | High7.4 | — | 0.7% | Aug 19, 2023 |
29Monitor | CVE-2020-18336No exploit | Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file typora · typora · CWE-79 | High7.4 | — | 0.6% | Oct 9, 2023 |
29Monitor | CVE-2024-33300No exploit | Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to executetypora · typora · CWE-79 | High7.3 | — | 0.6% | May 1, 2024 |
26Monitor | CVE-2023-2971No exploit | Typora Local File Disclosuretypora · typora · CWE-22 | Medium6.5 | — | 0.5% | Aug 19, 2023 |
25Monitor | CVE-2019-6803No exploit | typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.typora · typora · CWE-79 | Medium6.1 | — | 1.9% | Jan 25, 2019 |
25Monitor | CVE-2019-7296No exploit | typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.typora · typora · CWE-79 | Medium6.1 | — | 1.7% | Jan 31, 2019 |
25Monitor | CVE-2019-7295No exploit | typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.typora · typora · CWE-79 | Medium6.1 | — | 1.7% | Jan 31, 2019 |
24Monitor | CVE-2020-18737No exploit | An issue was discovered in Typora 0.9.67.typora · typora · CWE-79 | Medium6.1 | — | 1.3% | Feb 5, 2021 |
24Monitor | CVE-2020-18221No exploit | Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during bloctypora · typora · CWE-79 | Medium6.1 | — | 1.2% | May 26, 2021 |
24Monitor | CVE-2020-18748No exploit | Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration ertypora · typora · CWE-79 | Medium6.1 | — | 0.9% | Aug 19, 2021 |
24Monitor | CVE-2020-21058No exploit | Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.typora · typora · CWE-79 | Medium6.1 | — | 0.6% | Jun 20, 2023 |
24Monitor | CVE-2023-39703No exploit | A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via typora · typora · CWE-79 | Medium6.1 | — | 0.5% | Sep 1, 2023 |
24Monitor | CVE-2022-40011No exploit | Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then ustypora · typora · CWE-79 | Medium6.1 | — | 0.4% | Dec 23, 2022 |
24Monitor | CVE-2024-41481No exploit | Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.typora · typora · CWE-79 | Medium6.1 | — | 0.4% | Aug 12, 2024 |
24Monitor | CVE-2024-31783No exploit | Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a craftedtypora · typora · CWE-79 | Medium6.1 | — | 0.4% | Apr 16, 2024 |
24Monitor | CVE-2022-43668No exploit | Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the typora · typora · CWE-79 | Medium6.1 | — | 0.4% | Dec 7, 2022 |
24Monitor | CVE-2024-41482No exploit | Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.typora · typora · CWE-79 | Medium6.1 | — | 0.3% | Aug 12, 2024 |
24Monitor | CVE-2024-31784No exploit | An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted paytypora · typora · CWE-290 | Medium6.1 | — | 0.3% | Apr 16, 2024 |
- CVE-2023-231739Monitor
Typora DOM-Based Cross-site Scripting leading to Remote Code Execution
CriticalCVSS 9.6No exploitEPSS 2%typora · typoraAug 19, 2023
- CVE-2019-2037439Monitor
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution
CriticalCVSS 9.6No exploitEPSS 2%typora · typoraJan 9, 2020
- CVE-2019-1213733Monitor
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note
HighCVSS 7.8Proof of conceptEPSS 6%typora · typoraMay 16, 2019
- CVE-2019-1217232Monitor
Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demons
HighCVSS 7.8No exploitEPSS 2%typora · typoraMay 17, 2019
- CVE-2023-100331Monitor
Typora WSH JScript code injection
HighCVSS 7.8No exploitEPSS 0%typora · typoraMar 7, 2023
- CVE-2023-231629Monitor
Typora Local File Disclosure
HighCVSS 7.4No exploitEPSS 1%typora · typoraAug 19, 2023
- CVE-2020-1833629Monitor
Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file
HighCVSS 7.4No exploitEPSS 1%typora · typoraOct 9, 2023
- CVE-2024-3330029Monitor
Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute
HighCVSS 7.3No exploitEPSS 1%typora · typoraMay 1, 2024
- CVE-2023-297126Monitor
Typora Local File Disclosure
MediumCVSS 6.5No exploitEPSS 0%typora · typoraAug 19, 2023
- CVE-2019-680325Monitor
typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.
MediumCVSS 6.1No exploitEPSS 2%typora · typoraJan 25, 2019
- CVE-2019-729625Monitor
typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
MediumCVSS 6.1No exploitEPSS 2%typora · typoraJan 31, 2019
- CVE-2019-729525Monitor
typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
MediumCVSS 6.1No exploitEPSS 2%typora · typoraJan 31, 2019
- CVE-2020-1873724Monitor
An issue was discovered in Typora 0.9.67.
MediumCVSS 6.1No exploitEPSS 1%typora · typoraFeb 5, 2021
- CVE-2020-1822124Monitor
Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during bloc
MediumCVSS 6.1No exploitEPSS 1%typora · typoraMay 26, 2021
- CVE-2020-1874824Monitor
Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration er
MediumCVSS 6.1No exploitEPSS 1%typora · typoraAug 19, 2021
- CVE-2020-2105824Monitor
Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.
MediumCVSS 6.1No exploitEPSS 1%typora · typoraJun 20, 2023
- CVE-2023-3970324Monitor
A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via
MediumCVSS 6.1No exploitEPSS 0%typora · typoraSep 1, 2023
- CVE-2022-4001124Monitor
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then us
MediumCVSS 6.1No exploitEPSS 0%typora · typoraDec 23, 2022
- CVE-2024-4148124Monitor
Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.
MediumCVSS 6.1No exploitEPSS 0%typora · typoraAug 12, 2024
- CVE-2024-3178324Monitor
Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted
MediumCVSS 6.1No exploitEPSS 0%typora · typoraApr 16, 2024
- CVE-2022-4366824Monitor
Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the
MediumCVSS 6.1No exploitEPSS 0%typora · typoraDec 7, 2022
- CVE-2024-4148224Monitor
Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.
MediumCVSS 6.1No exploitEPSS 0%typora · typoraAug 12, 2024
- CVE-2024-3178424Monitor
An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted pay
MediumCVSS 6.1No exploitEPSS 0%typora · typoraApr 16, 2024