Skip to content
Noroxi

Typora records

23 published records for vendor typora.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
11
With a fix record
4.3%
Median publish → KEV
No record has entered KEV

All records

23 records
  • CVE-2023-2317
    39Monitor

    Typora DOM-Based Cross-site Scripting leading to Remote Code Execution

    CriticalCVSS 9.6No exploitEPSS 2%

    typora · typoraAug 19, 2023

  • A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution

    CriticalCVSS 9.6No exploitEPSS 2%

    typora · typoraJan 9, 2020

  • Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note

    HighCVSS 7.8Proof of conceptEPSS 6%

    typora · typoraMay 16, 2019

  • Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demons

    HighCVSS 7.8No exploitEPSS 2%

    typora · typoraMay 17, 2019

  • CVE-2023-1003
    31Monitor

    Typora WSH JScript code injection

    HighCVSS 7.8No exploitEPSS 0%

    typora · typoraMar 7, 2023

  • CVE-2023-2316
    29Monitor

    Typora Local File Disclosure

    HighCVSS 7.4No exploitEPSS 1%

    typora · typoraAug 19, 2023

  • Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file

    HighCVSS 7.4No exploitEPSS 1%

    typora · typoraOct 9, 2023

  • Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute

    HighCVSS 7.3No exploitEPSS 1%

    typora · typoraMay 1, 2024

  • CVE-2023-2971
    26Monitor

    Typora Local File Disclosure

    MediumCVSS 6.5No exploitEPSS 0%

    typora · typoraAug 19, 2023

  • CVE-2019-6803
    25Monitor

    typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.

    MediumCVSS 6.1No exploitEPSS 2%

    typora · typoraJan 25, 2019

  • CVE-2019-7296
    25Monitor

    typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.

    MediumCVSS 6.1No exploitEPSS 2%

    typora · typoraJan 31, 2019

  • CVE-2019-7295
    25Monitor

    typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.

    MediumCVSS 6.1No exploitEPSS 2%

    typora · typoraJan 31, 2019

  • An issue was discovered in Typora 0.9.67.

    MediumCVSS 6.1No exploitEPSS 1%

    typora · typoraFeb 5, 2021

  • Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during bloc

    MediumCVSS 6.1No exploitEPSS 1%

    typora · typoraMay 26, 2021

  • Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration er

    MediumCVSS 6.1No exploitEPSS 1%

    typora · typoraAug 19, 2021

  • Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.

    MediumCVSS 6.1No exploitEPSS 1%

    typora · typoraJun 20, 2023

  • A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via

    MediumCVSS 6.1No exploitEPSS 0%

    typora · typoraSep 1, 2023

  • Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then us

    MediumCVSS 6.1No exploitEPSS 0%

    typora · typoraDec 23, 2022

  • Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.

    MediumCVSS 6.1No exploitEPSS 0%

    typora · typoraAug 12, 2024

  • Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted

    MediumCVSS 6.1No exploitEPSS 0%

    typora · typoraApr 16, 2024

  • Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the

    MediumCVSS 6.1No exploitEPSS 0%

    typora · typoraDec 7, 2022

  • Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.

    MediumCVSS 6.1No exploitEPSS 0%

    typora · typoraAug 12, 2024

  • An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted pay

    MediumCVSS 6.1No exploitEPSS 0%

    typora · typoraApr 16, 2024