Freeplane is a mind-mapping and diagram editor whose vulnerability footprint centers on a single product and reflects the XML processing inherent to its document format and interchange capabilities. The durable signal is rooted in improper restriction of XML external entity references, a weakness class that arises in tools handling structured document formats. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freeplane over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000069MEDIUM FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This | Mar 13, 2018 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freeplane.
Media articles that mention a CVE ID that affects a product developed by Freeplane — matched by CVE ID, not by vendor name.