Joplin is an open-source note-taking and synchronization application that, despite a narrow product scope, occupies a prominent position in the landscape owing to its wide adoption across personal and small-team deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a corresponding tendency to acquire public exploit code. The exposure recurs through application-layer weakness classes including cross-site scripting, code injection, improper access control, and input validation defects, which are characteristic of web-facing note storage and synchronization functionality. Defenders should prioritize updates to this application given its frequent access to sensitive personal and organizational data; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joplin Project over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27134HIGH Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a privilege escalation v | Apr 30, 2025 | 8.8 | 39 | NO | YES |
CVE-2020-28249MEDIUM Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note. | Nov 6, 2020 | 6.1 | 30 | NO | YES |
CVE-2020-15930MEDIUM An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag. | Sep 24, 2020 | 6.1 | 30 | NO | YES |
CVE-2020-9038MEDIUM Joplin through 1.0.184 allows Arbitrary File Read via XSS. | Feb 17, 2020 | 5.4 | 30 | NO | YES |
CVE-2024-40643CRITICAL Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such | Sep 9, 2024 | 9.6 | 27 | NO | NO |
CVE-2025-24028CRITICAL Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences betw | Feb 7, 2025 | 9.6 | 26 | NO | NO |
CVE-2024-49362CRITICAL Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link with | Nov 14, 2024 | 9.6 | 26 | NO | NO |
CVE-2023-45673CRITICAL Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions allows clicking on a link in a PDF in an untrusted | Jun 21, 2024 | 9.0 | 26 | NO | NO |
CVE-2022-23340CRITICAL Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results. | Feb 8, 2022 | 9.8 | 24 | NO | NO |
CVE-2024-53268HIGH Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions attackers are able to abuse the fa | Nov 25, 2024 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joplin Project.
Media articles that mention a CVE ID that affects a product developed by Joplin Project — matched by CVE ID, not by vendor name.