Vulnerabilities > Leanote > Leanote > 1.3.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-09-30 | CVE-2020-26158 | Cross-site Scripting vulnerability in Leanote Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. | 9.6 |
2020-09-30 | CVE-2020-26157 | Cross-site Scripting vulnerability in Leanote Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. | 9.6 |
2019-07-11 | CVE-2019-1010003 | Cross-site Scripting vulnerability in Leanote Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS). | 6.1 |
2018-01-03 | CVE-2017-1000459 | Cross-site Scripting vulnerability in Leanote Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes | 6.1 |