Notable develops a focused healthcare platform product with a durable signal centered on web application input handling, specifically path traversal and cross-site scripting vulnerabilities that are common to server-side request routing and client-side template generation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Notable over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26198CRITICAL Notable v1.8.4 does not filter text editing, allowing attackers to execute arbitrary code via a crafted payload injected into the Title text field. | Mar 27, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-29281HIGH Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to | Apr 15, 2022 | 8.8 | 28 | NO | NO |
CVE-2020-16608CRITICAL Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true). | Dec 10, 2020 | 9.6 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Notable.
Media articles that mention a CVE ID that affects a product developed by Notable — matched by CVE ID, not by vendor name.