Evernote operates a suite of note-taking and web-clipping applications with significant reach across desktop, mobile, and web platforms, positioning the vendor's products at the interface between user content creation and cloud synchronization. Its vulnerability profile centers on input-handling and authentication weaknesses across the core Evernote application and complementary tools such as Web Clipper, with recurring flaws in cross-site scripting, command injection, path traversal, and improper permission assignment that are characteristic of applications bridging client, web, and server tiers. A meaningful share of the vendor's disclosures reach serious severity, and the weakness classes carry a moderate tendency toward public exploit availability. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Evernote over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10038HIGH Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.app/Contents/MacOS/Cal | May 31, 2019 | 7.8 | 36 | NO | YES |
CVE-2023-50643CRITICAL An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components. | Jan 9, 2024 | 9.8 | 33 | NO | NO |
CVE-2020-17759HIGH An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specia | Jun 24, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-17051HIGH Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving | Sep 30, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-20058HIGH In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-28634. | Dec 11, 2018 | 7.5 | 25 | NO | NO |
CVE-2016-4900HIGH Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory. | May 22, 2017 | 7.8 | 23 | NO | NO |
CVE-2019-12592MEDIUM A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote attackers to run arbitrary web script or HTML in | Jun 18, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-18524MEDIUM Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an | May 13, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-20351MEDIUM The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832. | Dec 22, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-19658MEDIUM The Markdown editor in YXBJ before 8.3.2 on macOS has stored XSS. This behavior may be encountered by some Evernote users; however, it is a vulnerability in YXBJ, not a vulnerabili | Mar 2, 2020 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Evernote.
Media articles that mention a CVE ID that affects a product developed by Evernote — matched by CVE ID, not by vendor name.