{"schema_version":1,"title":"Joplin vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 20 vulnerabilities in Joplin: 8 in the last 7 days and 8 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-59814, was published on 21 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/joplin","json_url":"https://junglewise.ai/threats/vendors/joplin.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/joplin","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":6,"all_time":20,"critical":0,"exploited":0,"last_7_days":8,"last_30_days":8,"last_90_days":8,"last_365_days":11},"latest":[{"cve":"CVE-2026-59814","cvss":7.6,"epss":0.0035,"slug":"cve-2026-59814-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin Server stored XSS in resource sharing via empty title","severity":"high","exploited":false,"published_at":"2026-09-21T22:16:57.05+00:00","url":"https://junglewise.ai/threats/cve-2026-59814-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-55210","cvss":7.4,"epss":0.0048,"slug":"cve-2026-55210-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin Server SAML authentication bypass to local account access","severity":"high","exploited":false,"published_at":"2026-09-21T22:16:56.89+00:00","url":"https://junglewise.ai/threats/cve-2026-55210-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-46650","cvss":4.4,"epss":0.003,"slug":"cve-2026-46650-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin XSS vulnerability in HTML note links","severity":"medium","exploited":false,"published_at":"2026-09-21T22:16:56.48+00:00","url":"https://junglewise.ai/threats/cve-2026-46650-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-59816","cvss":4.3,"epss":0.0036,"slug":"cve-2026-59816-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin Server path traversal in transcribe proxy","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:06.49+00:00","url":"https://junglewise.ai/threats/cve-2026-59816-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-55105","cvss":7.7,"epss":0.005,"slug":"cve-2026-55105-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin cross-site scripting in Fountain code blocks","severity":"high","exploited":false,"published_at":"2026-09-21T21:17:05.32+00:00","url":"https://junglewise.ai/threats/cve-2026-55105-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-49453","cvss":7,"epss":0.0041,"slug":"cve-2026-49453-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin path traversal in resource synchronization","severity":"high","exploited":false,"published_at":"2026-09-21T21:17:03.9+00:00","url":"https://junglewise.ai/threats/cve-2026-49453-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-49450","cvss":7.1,"epss":0.0018,"slug":"cve-2026-49450-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin Desktop unsigned update acceptance on Windows","severity":"high","exploited":false,"published_at":"2026-09-21T21:17:03.747+00:00","url":"https://junglewise.ai/threats/cve-2026-49450-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-46649","epss":0.0056,"slug":"cve-2026-46649-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin Server authentication brute force in SSO endpoint","severity":"info","exploited":false,"published_at":"2026-09-21T21:17:03.323+00:00","url":"https://junglewise.ai/threats/cve-2026-46649-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-34600","cvss":5.7,"slug":"cve-2026-34600-joplin-server-incorrect-authorization-in-delta-api","title":"Joplin Server incorrect authorization in delta API","severity":"medium","exploited":false,"published_at":"2026-05-19T23:16:57.29+00:00","url":"https://junglewise.ai/threats/cve-2026-34600-joplin-server-incorrect-authorization-in-delta-api"},{"cve":"CVE-2025-57798","cvss":5.5,"slug":"cve-2025-57798-joplin-denial-of-service-via-uncontrolled-resource-allocation-in","title":"Joplin denial of service via uncontrolled resource allocation in note titles","severity":"medium","exploited":false,"published_at":"2026-05-19T21:16:40.817+00:00","url":"https://junglewise.ai/threats/cve-2025-57798-joplin-denial-of-service-via-uncontrolled-resource-allocation-in"},{"cve":"CVE-2026-22810","cvss":8.2,"epss":0.0021,"slug":"cve-2026-22810-joplin-path-traversal-in-onenote-importer","title":"Joplin path traversal in OneNote importer","severity":"high","exploited":false,"published_at":"2026-05-18T21:16:39.373+00:00","url":"https://junglewise.ai/threats/cve-2026-22810-joplin-path-traversal-in-onenote-importer"},{"cve":"CVE-2023-37298","cvss":3.1,"epss":0.0057,"slug":"cve-2023-37298-joplin-cross-site-scripting-in-svg-editor","title":"Joplin Cross-site Scripting in SVG editor","severity":"low","exploited":false,"published_at":"2023-06-30T15:30:22+00:00","url":"https://junglewise.ai/threats/cve-2023-37298-joplin-cross-site-scripting-in-svg-editor"},{"cve":"CVE-2022-40277","cvss":3.1,"epss":0.0052,"slug":"cve-2022-40277-joplin-remote-code-execution-via-malicious-markdown-links","title":"Joplin Remote Code Execution via malicious markdown links","severity":"low","exploited":false,"published_at":"2022-10-01T00:00:20+00:00","url":"https://junglewise.ai/threats/cve-2022-40277-joplin-remote-code-execution-via-malicious-markdown-links"},{"cve":"CVE-2022-35131","cvss":3.1,"epss":0.0233,"slug":"cve-2022-35131-joplin-arbitrary-code-execution-via-node-title-injection","title":"Joplin arbitrary code execution via node title injection","severity":"low","exploited":false,"published_at":"2022-07-26T00:00:28+00:00","url":"https://junglewise.ai/threats/cve-2022-35131-joplin-arbitrary-code-execution-via-node-title-injection"},{"cve":"CVE-2021-37916","cvss":3.1,"epss":0.0073,"slug":"cve-2021-37916-joplin-cross-site-scripting-in-notes-via-form-elements","title":"Joplin Cross-site Scripting in notes via form elements","severity":"low","exploited":false,"published_at":"2022-05-24T19:09:53+00:00","url":"https://junglewise.ai/threats/cve-2021-37916-joplin-cross-site-scripting-in-notes-via-form-elements"},{"cve":"CVE-2018-1000534","cvss":3,"epss":0.0153,"slug":"cve-2018-1000534-joplin-cross-site-scripting-in-note-content","title":"Joplin cross-site scripting in note content","severity":"low","exploited":false,"published_at":"2022-05-14T03:06:11+00:00","url":"https://junglewise.ai/threats/cve-2018-1000534-joplin-cross-site-scripting-in-note-content"},{"cve":"CVE-2022-23340","cvss":3.1,"epss":0.0151,"slug":"cve-2022-23340-joplin-code-injection-remote-code-execution","title":"Joplin code injection remote code execution","severity":"low","exploited":false,"published_at":"2022-02-09T00:00:29+00:00","url":"https://junglewise.ai/threats/cve-2022-23340-joplin-code-injection-remote-code-execution"},{"cve":"CVE-2021-23431","cvss":3.1,"epss":0.004,"slug":"cve-2021-23431-joplin-cross-site-request-forgery-in-forms","title":"Joplin cross-site request forgery in forms","severity":"low","exploited":false,"published_at":"2021-09-02T17:09:05+00:00","url":"https://junglewise.ai/threats/cve-2021-23431-joplin-cross-site-request-forgery-in-forms"},{"cve":"CVE-2020-15930","cvss":3.1,"epss":0.0438,"slug":"cve-2020-15930-joplin-cross-site-scripting-in-html-embed-tag","title":"Joplin cross-site scripting in HTML embed tag","severity":"low","exploited":false,"published_at":"2021-05-07T16:29:05+00:00","url":"https://junglewise.ai/threats/cve-2020-15930-joplin-cross-site-scripting-in-html-embed-tag"},{"cve":"CVE-2020-9038","cvss":3.1,"epss":0.0357,"slug":"cve-2020-9038-joplin-cross-site-scripting-in-html-rendering","title":"Joplin cross-site scripting in HTML rendering","severity":"low","exploited":false,"published_at":"2020-10-13T17:29:25+00:00","url":"https://junglewise.ai/threats/cve-2020-9038-joplin-cross-site-scripting-in-html-rendering"}],"vendor":{"hub":true,"name":"Joplin","slug":"joplin","homepage":"https://joplinapp.org/","description":"Joplin is an open source note-taking and to-do application with synchronization capabilities.","url":"https://junglewise.ai/threats/vendors/joplin"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":8}],"most_severe":[{"cve":"CVE-2026-22810","cvss":8.2,"epss":0.0021,"slug":"cve-2026-22810-joplin-path-traversal-in-onenote-importer","title":"Joplin path traversal in OneNote importer","severity":"high","exploited":false,"published_at":"2026-05-18T21:16:39.373+00:00","url":"https://junglewise.ai/threats/cve-2026-22810-joplin-path-traversal-in-onenote-importer"},{"cve":"CVE-2026-55105","cvss":7.7,"epss":0.005,"slug":"cve-2026-55105-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin cross-site scripting in Fountain code blocks","severity":"high","exploited":false,"published_at":"2026-09-21T21:17:05.32+00:00","url":"https://junglewise.ai/threats/cve-2026-55105-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-59814","cvss":7.6,"epss":0.0035,"slug":"cve-2026-59814-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin Server stored XSS in resource sharing via empty title","severity":"high","exploited":false,"published_at":"2026-09-21T22:16:57.05+00:00","url":"https://junglewise.ai/threats/cve-2026-59814-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-55210","cvss":7.4,"epss":0.0048,"slug":"cve-2026-55210-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin Server SAML authentication bypass to local account access","severity":"high","exploited":false,"published_at":"2026-09-21T22:16:56.89+00:00","url":"https://junglewise.ai/threats/cve-2026-55210-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-49450","cvss":7.1,"epss":0.0018,"slug":"cve-2026-49450-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin Desktop unsigned update acceptance on Windows","severity":"high","exploited":false,"published_at":"2026-09-21T21:17:03.747+00:00","url":"https://junglewise.ai/threats/cve-2026-49450-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-49453","cvss":7,"epss":0.0041,"slug":"cve-2026-49453-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin path traversal in resource synchronization","severity":"high","exploited":false,"published_at":"2026-09-21T21:17:03.9+00:00","url":"https://junglewise.ai/threats/cve-2026-49453-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-34600","cvss":5.7,"slug":"cve-2026-34600-joplin-server-incorrect-authorization-in-delta-api","title":"Joplin Server incorrect authorization in delta API","severity":"medium","exploited":false,"published_at":"2026-05-19T23:16:57.29+00:00","url":"https://junglewise.ai/threats/cve-2026-34600-joplin-server-incorrect-authorization-in-delta-api"},{"cve":"CVE-2025-57798","cvss":5.5,"slug":"cve-2025-57798-joplin-denial-of-service-via-uncontrolled-resource-allocation-in","title":"Joplin denial of service via uncontrolled resource allocation in note titles","severity":"medium","exploited":false,"published_at":"2026-05-19T21:16:40.817+00:00","url":"https://junglewise.ai/threats/cve-2025-57798-joplin-denial-of-service-via-uncontrolled-resource-allocation-in"},{"cve":"CVE-2026-46650","cvss":4.4,"epss":0.003,"slug":"cve-2026-46650-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin XSS vulnerability in HTML note links","severity":"medium","exploited":false,"published_at":"2026-09-21T22:16:56.48+00:00","url":"https://junglewise.ai/threats/cve-2026-46650-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-59816","cvss":4.3,"epss":0.0036,"slug":"cve-2026-59816-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin Server path traversal in transcribe proxy","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:06.49+00:00","url":"https://junglewise.ai/threats/cve-2026-59816-joplin-is-an-open-source-note-taking-and-to-do-application-that"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Joplin","slug":"joplin","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/joplin"}]}