Vulnerabilities > Boostnote

DATE CVE VULNERABILITY TITLE RISK
2021-09-17 CVE-2021-41392 Injection vulnerability in Boostnote
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution.
network
low complexity
boostnote CWE-74
critical
9.8
2018-07-08 CVE-2018-13433 Cross-site Scripting vulnerability in Boostnote 0.11.7
Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element.
network
low complexity
boostnote CWE-79
6.1