Back to Database
Status published
Critical
CVE-2024-40643
Joplin has a parsing error leading to Cross-site Scripting (XSS)
Vulnerability Description
Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-40643
Credits & Attribution
No credits recorded in the NVD database.
References
More from laurent22
View All →CVE-2025-57798
Joplin has Denial of Service (DoS) via Uncontrolled Resource Allocation through Title Input
Medium
5.5
CVE-2025-27409
Joplin Server Vulnerable to Path Traversal
High
7.5
CVE-2025-27134
Privilege escalation in Joplin server via user patch endpoint
High
8.8
CVE-2025-25187
Cross-site Scripting in Goto Anything allows arbitrary code execution in Joplin
High
7.8
CVE-2025-24028
Cross-site Scripting (XSS) in Rich Text Editor allows arbitrary code execution in Joplin
High
7.8
Affected Vendor
laurent22
View all reports →Affected Software
joplin
Vulnerable Versions:
< 3.0.15
Timeline
Official Publish:
September 9th, 2024
Last Modified:
September 9th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H