Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Joplin Project

First CVE: Jun 26, 2018Active for: 8 yearsTotal CVEs: 22
37.0
VTI Score
Medium

Joplin is an open-source note-taking and synchronization application that, despite a narrow product scope, occupies a prominent position in the landscape owing to its wide adoption across personal and small-team deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a corresponding tendency to acquire public exploit code. The exposure recurs through application-layer weakness classes including cross-site scripting, code injection, improper access control, and input validation defects, which are characteristic of web-facing note storage and synchronization functionality. Defenders should prioritize updates to this application given its frequent access to sensitive personal and organizational data; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
3.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Joplin Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 26, 2018
8 years ago
Most Recent CVE
Apr 30, 2025
452 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-27134HIGH
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a privilege escalation v
Apr 30, 20258.839NOYES
CVE-2020-28249MEDIUM
Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.
Nov 6, 20206.130NOYES
CVE-2020-15930MEDIUM
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
Sep 24, 20206.130NOYES
CVE-2020-9038MEDIUM
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
Feb 17, 20205.430NOYES
CVE-2024-40643CRITICAL
Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such
Sep 9, 20249.627NONO
CVE-2025-24028CRITICAL
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences betw
Feb 7, 20259.626NONO
CVE-2024-49362CRITICAL
Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link with
Nov 14, 20249.626NONO
CVE-2023-45673CRITICAL
Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions allows clicking on a link in a PDF in an untrusted
Jun 21, 20249.026NONO
CVE-2022-23340CRITICAL
Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.
Feb 8, 20229.824NONO
CVE-2024-53268HIGH
Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions attackers are able to abuse the fa
Nov 25, 20248.823NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
64%
14%
23%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.5%)
Network21 (95.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (13.6%)
Unknown0 (0.0%)
Required19 (86.4%)
Privileges Required
Low8 (36.4%)
High0 (0.0%)
None14 (63.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.5% of CVEs· 95th percentile
ExploitDB
3 CVEs
13.6% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Joplin Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Joplin Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Joplin Project's Products

View all 2 CNAs →

Top CWEs