Blinko
Vendor:
First CVE: Mar 23, 2026 · Active for under a year
10
Total CVEs
More Total CVEs than 89% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Blinko over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2026
4 months ago
Most Recent CVE
Mar 23, 2026
127 days ago
CVE Severity & Scoring
Blinko10 CVEs
70%
30%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (40.0%)
High1 (10.0%)
None5 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-23482HIGH Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform permission checks on the temp/ path and does not filter path tra | Mar 23, 2026 | 7.5 | 35 | NO | YES |
CVE-2026-23486MEDIUM Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including usernames, roles, and account creat | Mar 23, 2026 | 5.3 | 29 | NO | YES |
CVE-2026-23483MEDIUM Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the fina | Mar 23, 2026 | 5.3 | 29 | NO | YES |
CVE-2026-23480HIGH Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability. The upsertUser endpoint has 3 issues: it is missing superAd | Mar 23, 2026 | 8.8 | 25 | NO | NO |
CVE-2026-23882HIGH Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying arbitrary commands and argumen | Mar 23, 2026 | 7.2 | 24 | NO | NO |
CVE-2026-23487MEDIUM Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.detail Endpoint Leaks the Superadmin Token. This issue has been | Mar 23, 2026 | 6.5 | 20 | NO | NO |
CVE-2026-23484MEDIUM Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal to write files anywhere on the f | Mar 23, 2026 | 6.5 | 20 | NO | NO |
CVE-2026-23481MEDIUM Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write vulnerability in saveAdditionalDevFile. This issue has been | Mar 23, 2026 | 6.5 | 20 | NO | NO |
CVE-2026-23488MEDIUM Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an unauthorized access vulnerability, allowing attackers to post c | Mar 23, 2026 | 5.3 | 19 | NO | NO |
CVE-2026-23485MEDIUM Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal sequences, allowing enumeration of file existence on the ser | Mar 23, 2026 | 5.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
30.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Blinko
Top CWEs
Versions
No cataloged versions.