{"api_version":"v1","generated_at":"2026-10-08T15:35:00+00:00","product":{"cve_count":30,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-laurent22-joplin-5df47921576b","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/joplin","name":"joplin","next_cursor":null,"observations":[{"affected":"joplin: < 3.7.13","affected_versions_present":true,"cve_id":"CVE-2026-105786","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105786","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-06T17:39:22.558Z","patch_url":"","primary_source":"","published":"2026-10-05T23:18:27.313Z"},{"affected":"joplin: < 3.7.2","affected_versions_present":true,"cve_id":"CVE-2026-105785","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105785","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-08T02:35:28.061Z","patch_url":"","primary_source":"","published":"2026-10-05T23:12:45.286Z"},{"affected":"joplin: < 3.7.13","affected_versions_present":true,"cve_id":"CVE-2026-105784","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105784","fixed":"3.7.13.","last_modified":"2026-10-06T13:16:49.135Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-6h4j-86j4-x4q4","primary_source":"","published":"2026-10-05T23:11:35.029Z"},{"affected":"joplin: < 3.7.13","affected_versions_present":true,"cve_id":"CVE-2026-105783","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105783","fixed":"3.7.13.","last_modified":"2026-10-06T14:47:45.876Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-9728-v7ww-mxjv","primary_source":"","published":"2026-10-05T23:10:26.012Z"},{"affected":"joplin: < 3.7.2","affected_versions_present":true,"cve_id":"CVE-2026-46650","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46650","fixed":"3.7.2.","last_modified":"2026-09-29T13:57:46.486Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-x9vj-jrqf-9wcm","primary_source":"","published":"2026-09-21T21:16:12.297Z"},{"affected":"joplin: < 3.7.7","affected_versions_present":true,"cve_id":"CVE-2026-59815","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59815","fixed":"3.7.7.","last_modified":"2026-09-24T22:49:51.891Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-qq59-gg3w-pf7v","primary_source":"","published":"2026-09-21T21:15:15.882Z"},{"affected":"joplin: < 3.7.2","affected_versions_present":true,"cve_id":"CVE-2026-55210","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55210","fixed":"3.7.2.","last_modified":"2026-09-22T13:07:10.486Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-5px3-4f5x-hjc5","primary_source":"","published":"2026-09-21T21:14:31.267Z"},{"affected":"joplin: < 3.7.7","affected_versions_present":true,"cve_id":"CVE-2026-59814","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59814","fixed":"3.7.7.","last_modified":"2026-09-22T13:29:52.943Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-mx98-7h4g-6gmh","primary_source":"","published":"2026-09-21T21:13:17.395Z"},{"affected":"joplin: < 3.6.15, >= 3.7.0, < 3.7.2","affected_versions_present":true,"cve_id":"CVE-2026-55105","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55105","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T22:48:03.831Z","patch_url":"","primary_source":"","published":"2026-09-21T20:59:52.292Z"},{"affected":"joplin: < 3.7.2","affected_versions_present":true,"cve_id":"CVE-2026-46649","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46649","fixed":"3.7.2.","last_modified":"2026-09-28T20:18:49.471Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-6vwc-4hrg-qp5h","primary_source":"","published":"2026-09-21T20:58:04.456Z"},{"affected":"joplin: < 3.7.2","affected_versions_present":true,"cve_id":"CVE-2026-55179","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55179","fixed":"3.7.2.","last_modified":"2026-09-22T13:08:49.691Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-r865-g55x-3mfc","primary_source":"","published":"2026-09-21T20:56:31.906Z"},{"affected":"joplin: < 3.7.7","affected_versions_present":true,"cve_id":"CVE-2026-59816","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59816","fixed":"3.7.7.","last_modified":"2026-09-22T13:30:48.089Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-r7wp-3494-fwf4","primary_source":"","published":"2026-09-21T20:54:39.684Z"},{"affected":"joplin: >= 1.4.0, < 3.7.2","affected_versions_present":true,"cve_id":"CVE-2026-49449","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49449","fixed":"3.7.2.","last_modified":"2026-09-28T20:15:24.088Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-9m2r-pv96-jxr3","primary_source":"","published":"2026-09-21T20:52:11.164Z"},{"affected":"joplin: < 3.6.15, >= 3.7.0, < 3.7.2","affected_versions_present":true,"cve_id":"CVE-2026-49453","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49453","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-22T13:31:37.953Z","patch_url":"","primary_source":"","published":"2026-09-21T20:50:28.455Z"},{"affected":"joplin: < 3.7.2","affected_versions_present":true,"cve_id":"CVE-2026-49450","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49450","fixed":"3.7.2.","last_modified":"2026-09-22T13:12:32.859Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-9wp7-hr9m-3273","primary_source":"","published":"2026-09-21T20:49:04.423Z"},{"affected":"< 3.5.3","affected_versions_present":true,"cve_id":"CVE-2026-34600","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34600","fixed":"3.5.3.","last_modified":"2026-05-20T14:10:38.820Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-88x4-77rc-jw94","primary_source":"","published":"2026-05-19T22:28:28.893Z"},{"affected":"< 3.7.1","affected_versions_present":true,"cve_id":"CVE-2025-57798","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-57798","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-20T14:55:22.365Z","patch_url":"","primary_source":"","published":"2026-05-19T20:24:35.088Z"},{"affected":"< 3.5.7","affected_versions_present":true,"cve_id":"CVE-2026-22810","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22810","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-20T03:55:23.355Z","patch_url":"https://github.com/laurent22/joplin/commit/791668455e1aae50501ff57ea4783b3fba9d377c","primary_source":"","published":"2026-05-18T20:23:57.607Z"},{"affected":"< 3.3.3","affected_versions_present":true,"cve_id":"CVE-2025-27134","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27134","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-30T15:11:12.895Z","patch_url":"https://github.com/laurent22/joplin/commit/12baa9827dac9da903f244c9f358e3deb264e228","primary_source":"","published":"2025-04-30T14:55:10.285Z"},{"affected":"< 3.3.3","affected_versions_present":true,"cve_id":"CVE-2025-27409","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27409","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-30T15:11:59.209Z","patch_url":"https://github.com/laurent22/joplin/pull/11916","primary_source":"","published":"2025-04-30T14:55:07.846Z"},{"affected":"< 3.1.24","affected_versions_present":true,"cve_id":"CVE-2025-25187","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-25187","fixed":"3.1.24","last_modified":"2025-02-10T17:15:09.979Z","patch_url":"https://github.com/laurent22/joplin/commit/360ece6f8873ef81afbfb98b25faad696ffccdb6","primary_source":"","published":"2025-02-07T22:38:20.068Z"},{"affected":">= 3.2.6, < 3.2.12","affected_versions_present":true,"cve_id":"CVE-2025-24028","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-24028","fixed":"3.2.12","last_modified":"2025-02-10T17:17:41.159Z","patch_url":"https://github.com/laurent22/joplin/commit/2a058ed8097c2502e152b26394dc1917897f5817","primary_source":"","published":"2025-02-07T22:23:07.275Z"},{"affected":"< 3.2.8","affected_versions_present":true,"cve_id":"CVE-2024-55630","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-55630","fixed":"3.2.8","last_modified":"2025-02-10T17:18:47.395Z","patch_url":"https://github.com/laurent22/joplin/commit/e70efcbd60ce62f06e77c183b362c74e636c02d9","primary_source":"","published":"2025-02-07T22:23:04.109Z"},{"affected":"< 3.0.3","affected_versions_present":true,"cve_id":"CVE-2024-53268","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53268","fixed":"3.0.3","last_modified":"2024-11-25T19:38:18.292Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-pc5v-xp44-5mgv","primary_source":"","published":"2024-11-25T19:22:17.131Z"},{"affected":"< 3.1","affected_versions_present":true,"cve_id":"CVE-2024-49362","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-49362","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-11-14T21:39:43.794Z","patch_url":"","primary_source":"","published":"2024-11-14T17:37:09.700Z"},{"affected":"< 3.0.15","affected_versions_present":true,"cve_id":"CVE-2024-40643","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-40643","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-09T14:52:47.111Z","patch_url":"https://github.com/laurent22/joplin/commit/b220413a9b5ed55fb1f565ac786a5c231da8bc87","primary_source":"","published":"2024-09-09T14:28:20.920Z"},{"affected":"< 2.12.9","affected_versions_present":true,"cve_id":"CVE-2023-37898","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-37898","fixed":"2.12.9","last_modified":"2024-08-02T17:23:27.755Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-hjmq-3qh4-g2r8","primary_source":"","published":"2024-06-21T19:45:19.982Z"},{"affected":"< 2.12.10","affected_versions_present":true,"cve_id":"CVE-2023-38506","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-38506","fixed":"2.12.10","last_modified":"2024-08-02T17:46:55.757Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-m59c-9rrj-c399","primary_source":"","published":"2024-06-21T19:43:24.161Z"},{"affected":"< 2.12.8","affected_versions_present":true,"cve_id":"CVE-2023-39517","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-39517","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T18:10:21.108Z","patch_url":"https://github.com/laurent22/joplin/commit/7c52c3e9a81a52ef1b42a951f9deb9d378d59b0f","primary_source":"","published":"2024-06-21T19:41:48.945Z"},{"affected":"< 2.13.3","affected_versions_present":true,"cve_id":"CVE-2023-45673","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-45673","fixed":"2.13.3.","last_modified":"2024-08-02T20:21:16.844Z","patch_url":"https://github.com/laurent22/joplin/security/advisories/GHSA-g8qx-5vcm-3x59","primary_source":"","published":"2024-06-21T19:38:22.764Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"laurent22"}}
