Inkdrop is a note-taking and markdown editing application with a modest vulnerability footprint centered on client-side and command-handling attack surface. The durable signal reflects input-processing weaknesses across its products, including cross-site scripting, code injection, and OS command injection vulnerabilities that arise in web-page generation and external command execution contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inkdrop over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20745HIGH Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet containing an invalid iframe into | Jun 28, 2021 | 7.8 | 25 | NO | NO |
CVE-2023-44141HIGH Inkdrop prior to v5.6.0 allows a local attacker to conduct a code injection attack by having a legitimate user open a specially crafted markdown file. | Oct 30, 2023 | 7.8 | 22 | NO | NO |
CVE-2022-46603MEDIUM An issue in Inkdrop v5.4.1 allows attackers to execute arbitrary commands via uploading a crafted markdown file. | Jan 9, 2023 | 6.1 | 21 | NO | NO |
CVE-2022-38639MEDIUM A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Post | Sep 9, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inkdrop.
Media articles that mention a CVE ID that affects a product developed by Inkdrop — matched by CVE ID, not by vendor name.