The Vnote Project maintains a note-taking application with a documented exposure centered on cross-site scripting vulnerabilities arising from improper neutralization of user input during web page generation. This represents a typical application-layer input-handling weakness for web-facing productivity software; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vnote Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-41662CRITICAL VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown rendering functionality of versions 3.18.1 and prior of the VNote no | Jul 24, 2024 | 9.6 | 28 | NO | NO |
CVE-2023-5701MEDIUM A vulnerability has been found in vnotex vnote up to 3.17.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Markdown File | Oct 23, 2023 | 6.1 | 19 | NO | NO |
CVE-2019-8419MEDIUM VNote 2.2 has XSS via a new text note. | Feb 17, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vnote Project.
Media articles that mention a CVE ID that affects a product developed by Vnote Project — matched by CVE ID, not by vendor name.