Vulnerabilities > Boostnote

DATE CVE VULNERABILITY TITLE RISK
2021-09-17 CVE-2021-41392 Injection vulnerability in Boostnote 0.11.7
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution.
network
low complexity
boostnote CWE-74
7.5
2018-07-08 CVE-2018-13433 Cross-site Scripting vulnerability in Boostnote 0.11.7
Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element.
network
boostnote CWE-79
4.3