Vulnerabilities (CVE)

Filtered by vendor Typora Subscribe
Filtered by product Typora
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-2971 3 Linux, Microsoft, Typora 3 Linux Kernel, Windows, Typora 2023-08-24 N/A 6.5 MEDIUM
Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora.
CVE-2020-18748 1 Typora 1 Typora 2021-08-23 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration error in the mathematical formula blocks. This is a different vulnerability from CVE-2020-18221.
CVE-2020-18221 1 Typora 1 Typora 2021-05-28 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during block rendering of a mathematical formula.
CVE-2020-18737 1 Typora 1 Typora 2021-02-08 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Typora 0.9.67. There is an XSS vulnerability that causes Remote Code Execution.
CVE-2019-7295 1 Typora 1 Typora 2019-02-01 4.3 MEDIUM 6.1 MEDIUM
typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
CVE-2019-7296 1 Typora 1 Typora 2019-02-01 4.3 MEDIUM 6.1 MEDIUM
typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
CVE-2019-6803 1 Typora 1 Typora 2019-01-25 4.3 MEDIUM 6.1 MEDIUM
typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.