Leanote is a note-taking and knowledge-management platform with a modest but prominent vulnerability profile centered on its core application and desktop client. Its vulnerabilities skew toward serious outcomes, with a notable share reaching critical severity, and recur through application-layer input-handling weakness classes—specifically cross-site scripting and path-traversal flaws—that are characteristic of web-facing content-management systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Leanote over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26158CRITICAL Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration. | Sep 30, 2020 | 9.6 | 28 | NO | NO |
CVE-2020-26157CRITICAL Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration. | Sep 30, 2020 | 9.6 | 28 | NO | NO |
CVE-2021-4263MEDIUM A vulnerability, which was classified as problematic, has been found in leanote 2.6.1. This issue affects the function define of the file public/js/plugins/history.js. The manipula | Dec 21, 2022 | 6.1 | 22 | NO | NO |
CVE-2019-1010003MEDIUM Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS). | Jul 11, 2019 | 6.1 | 22 | NO | NO |
CVE-2021-43721MEDIUM Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : <video src=x onerror=(function(){require('ch | Mar 28, 2022 | 6.1 | 21 | NO | NO |
CVE-2018-18553MEDIUM Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page. | Oct 22, 2018 | 6.1 | 21 | NO | NO |
CVE-2017-1000459MEDIUM Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes | Jan 3, 2018 | 6.1 | 21 | NO | NO |
CVE-2017-1000492MEDIUM Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration | Jan 3, 2018 | 6.1 | 20 | NO | NO |
CVE-2024-0849MEDIUM Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR. | Feb 7, 2024 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Leanote.
Media articles that mention a CVE ID that affects a product developed by Leanote — matched by CVE ID, not by vendor name.