Vendor
Multiple Vulnerabilities in Joplin
2 TTPsJoplin is affected by multiple vulnerabilities that allow a remote attacker to execute arbitrary code, escalate privileges, bypass security controls, perform cross-site scripting (XSS), or manipulate sensitive data, potentially leading to a full account takeover.
Multiple Vulnerabilities in Joplin Allow for DoS, Information Disclosure, and Arbitrary File Overwrite
2 rules 1 TTPMultiple vulnerabilities in Joplin allow an attacker to perform a denial of service attack, disclose sensitive information, or overwrite arbitrary files, potentially leading to arbitrary code execution.
Joplin OneNote Importer Path Traversal Vulnerability (CVE-2026-22810)
2 rules 2 TTPsA path traversal vulnerability exists in the OneNote importer of Joplin versions 3.5.6 and earlier. By importing a crafted .one file, an attacker can overwrite arbitrary files on the disk, potentially leading to privilege escalation and remote code execution. The vulnerability stems from the lack of sanitization of embedded file names within the OneNote converter, allowing filenames containing directory traversal sequences like `../../`.