BoostnoteCVEs & Vulnerabilities
2 CVEs affecting Boostnote products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
boostnote 2
CVE-2021-41392CRITICAL
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.
18 Sep 2021
9.8
CVSS
CVE-2018-13433MEDIUM
Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element.
8 Jul 2018
6.1
CVSS
← PrevPage 1 / 1Next →