Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Typora

First CVE: Jan 25, 2019Active for: 7 yearsTotal CVEs: 23
29.0
VTI Score
Low

Typora is a markdown editor with modest but notable prominence in the vulnerability landscape, concentrated in a single widely used product for document composition and note-taking. Its disclosures cluster around input-handling and trust-boundary weaknesses including cross-site scripting, path traversal, authentication bypass, and code injection, reflecting the challenges of rendering and processing untrusted markdown content in a desktop application with web-technology foundations. A meaningful share of vulnerabilities affecting this vendor reach critical severity, underscoring the risk when a document editor can execute or access system resources beyond its intended scope. Defenders should treat Typora updates with attention to the product's role in handling potentially adversarial documents, particularly in environments where user-supplied markdown files are processed. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Typora over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 25, 2019
7 years ago
Most Recent CVE
Aug 12, 2024
712 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-12137HIGH
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.
May 16, 20197.838NOYES
CVE-2023-2317CRITICAL
DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora main windo
Aug 19, 20239.629NONO
CVE-2019-20374CRITICAL
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit
Jan 9, 20209.628NONO
CVE-2019-12172HIGH
Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstrated by file:\\\ on macOS or Linux, or
May 17, 20197.825NONO
CVE-2023-2316HIGH
Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absol
Aug 19, 20237.423NONO
CVE-2020-18336HIGH
Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file exporting function.
Oct 10, 20237.422NONO
CVE-2020-18748MEDIUM
Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration error in the mathematical formula blocks.
Aug 19, 20216.122NONO
CVE-2019-6803MEDIUM
typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.
Jan 25, 20196.122NONO
CVE-2024-33300HIGH
Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrary code by uploading Markdown fi
May 1, 20247.321NONO
CVE-2020-21058MEDIUM
Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.
Jun 20, 20236.121NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
65%
26%
9%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (17.4%)
Network19 (82.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (4.3%)
Unknown0 (0.0%)
Required22 (95.7%)
Privileges Required
Low1 (4.3%)
High0 (0.0%)
None22 (95.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Typora.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Typora — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Typora's Products

View all 4 CNAs →

Top CWEs