Trilium Project maintains a self-hosted note-taking and knowledge-management application that, despite a narrow product footprint, has gained prominence in the personal-information-management space. The observed vulnerability signal centers on cross-site scripting weaknesses in web-page generation, reflecting the application's role as a browser-based interface for structured data storage and retrieval.
The number and severity of CVEs published that impact products developed by Trilium Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2365MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3. | Jul 10, 2022 | 5.4 | 21 | NO | NO |
CVE-2023-3067MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4. | Jun 2, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trilium Project.
Media articles that mention a CVE ID that affects a product developed by Trilium Project — matched by CVE ID, not by vendor name.