Known Vulnerabilities for products from Leanote
Listed below are 9 of the newest known vulnerabilities associated with the vendor "Leanote".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2024-0849 json | Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR. | Not Provided | 2024-02-07 | 2026-04-20 |
| CVE-2021-43721 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2022-03-28 | 2022-03-31 |
| CVE-2021-4263 json | A vulnerability, which was classified as problematic, has been found in leanote 2.6.1. This issue affects the function define... | 6.1 - MEDIUM | 2022-12-21 | 2023-11-16 |
| CVE-2020-26158 json | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads... | 9.6 - CRITICAL | 2020-09-30 | 2020-10-05 |
| CVE-2020-26157 json | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execu... | 9.6 - CRITICAL | 2020-09-30 | 2020-10-05 |
| CVE-2019-1010003 json | Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS). | 6.1 - MEDIUM | 2019-07-11 | 2019-07-12 |
| CVE-2018-18553 json | Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page. | 6.1 - MEDIUM | 2018-10-22 | 2018-12-04 |
| CVE-2017-1000492 json | Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration | 6.1 - MEDIUM | 2018-01-03 | 2018-01-17 |
| CVE-2017-1000459 json | Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes | 6.1 - MEDIUM | 2018-01-03 | 2018-01-17 |