Streetwriters' vulnerability footprint is concentrated in its Notesnook note-taking application across desktop and mobile platforms, with the durable signal centered on application-layer input-handling issues such as cross-site scripting and code injection. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Streetwriters over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42090CRITICAL Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS | May 4, 2026 | 9.6 | 36 | NO | NO |
CVE-2026-33976CRITICAL Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code exe | Mar 27, 2026 | 9.6 | 34 | NO | NO |
CVE-2026-33955HIGH Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote cod | Mar 27, 2026 | 8.6 | 30 | NO | NO |
CVE-2026-33978MEDIUM Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share / web clip flow because attacke | Apr 1, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-31876MEDIUM Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in Notesnook's editor embed componen | Mar 11, 2026 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Streetwriters.
Media articles that mention a CVE ID that affects a product developed by Streetwriters — matched by CVE ID, not by vendor name.