Joplin is a focused note-taking and document management application with a modest vulnerability footprint centered on web-facing input handling and request validation. Its observed weakness classes—cross-site request forgery, improper input validation, cross-site scripting, and path traversal—reflect the attack surface inherent to web-based note storage and synchronization; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joplinapp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35131CRITICAL Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles. | Jul 25, 2022 | 9.0 | 32 | NO | NO |
CVE-2026-22810HIGH Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the impo | May 18, 2026 | 7.3 | 31 | NO | NO |
CVE-2021-23431HIGH The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms. | Aug 24, 2021 | 8.8 | 26 | NO | NO |
CVE-2022-40277HIGH Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible b | Sep 30, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joplinapp.
Media articles that mention a CVE ID that affects a product developed by Joplinapp — matched by CVE ID, not by vendor name.