Known vulnerabilities in Joplin Server
Vendor:
Joplinapp
Software:
Joplin Server
Software CPE:
cpe:2.3:a:joplinapp:joplin_server:*:*:*:*:*:*:*:*
Website:
https://joplinapp.org/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
3.7.1
3.6.1
3.5.2
3.5.1
3.4.4
3.4.3
3.4.2
3.4.1
3.3.13
3.3.12
3.3.11
3.3.10
3.3.9
3.3.8
3.3.7
3.3.6
3.3.5
3.3.4
3.3.3
3.3.2
3.3.1
3.0.1
2.14.2
2.14.1
2.13.5
2.13.4
2.13.3
2.13.2
2.13.1
2.12.1
2.11.2
2.11.1
2.10.11
2.10.10
2.10.9
2.10.8
2.10.7
2.10.6
2.10.5
2.10.4
2.10.3
2.10.2
2.10.1
2.9.7
2.9.6
2.9.5
2.9.4
2.9.3
2.9.2
2.9.1
2.7.4
2.7.3
2.7.2
2.7.1
2.6.14
2.6.13
2.6.12
2.6.11
2.6.10
2.6.9
2.6.8
2.6.7
2.6.6
2.6.5
2.6.4
2.6.3
2.6.2
2.6.1
2.5.10
2.5.9
2.5.8
2.5.7
2.5.6
2.5.5
2.5.4
2.5.3
2.5.2
2.5.1
2.4.2
2.2.10
2.1.1
2.0.14
2.0.13
2.0.12
2.0.11
2.0.10
2.0.7
2.0.6
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
1.7.2
1.6.4
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU132299 - Improper Access Control CVE-2026-34600 |
CWE-284 | Low | 3.6.1 | 26.05.2026 |
SB2026052626 |
||
| #VU132297 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-27409 |
CWE-22 | Medium | 3.3.4 | 30.04.2025 |
SB2025043047 |
||
| #VU132298 - Improper Access Control CVE-2025-27134 |
CWE-284 | Medium | 3.3.3 | 30.04.2025 |
SB2025043046 |