CVE-2025-24028 is a critical cross-site scripting (XSS) vulnerability in Joplin, a note-taking application, affecting both its Rich Text Editor and Markdown viewer. The flaw stems from discrepancies in how Joplin's HTML sanitizer and web browsers handle comments, allowing malicious scripts to execute when untrusted notes are opened. With a CVSS score of 9.6 (CRITICAL), this vulnerability has a network attack vector, low attack complexity, and high potential impact on confidentiality, integrity, and availability, requiring user interaction to exploit. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.12CPE matchmatch criteria | cpe:2.3:a:joplin_project:joplin:*:*:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.