Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY30 SECURITY RECORDS

laurent22

joplin

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at joplin, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-105786 5 Oct 2026 joplin: < 3.7.13 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-105785 5 Oct 2026 joplin: < 3.7.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-105784 5 Oct 2026 joplin: < 3.7.13 3.7.13. Update reference ↗
CVE-2026-105783 5 Oct 2026 joplin: < 3.7.13 3.7.13. Update reference ↗
CVE-2026-46650 21 Sep 2026 joplin: < 3.7.2 3.7.2. Update reference ↗
CVE-2026-59815 21 Sep 2026 joplin: < 3.7.7 3.7.7. Update reference ↗
CVE-2026-55210 21 Sep 2026 joplin: < 3.7.2 3.7.2. Update reference ↗
CVE-2026-59814 21 Sep 2026 joplin: < 3.7.7 3.7.7. Update reference ↗
CVE-2026-55105 21 Sep 2026 joplin: < 3.6.15, >= 3.7.0, < 3.7.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-46649 21 Sep 2026 joplin: < 3.7.2 3.7.2. Update reference ↗
CVE-2026-55179 21 Sep 2026 joplin: < 3.7.2 3.7.2. Update reference ↗
CVE-2026-59816 21 Sep 2026 joplin: < 3.7.7 3.7.7. Update reference ↗
CVE-2026-49449 21 Sep 2026 joplin: >= 1.4.0, < 3.7.2 3.7.2. Update reference ↗
CVE-2026-49453 21 Sep 2026 joplin: < 3.6.15, >= 3.7.0, < 3.7.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-49450 21 Sep 2026 joplin: < 3.7.2 3.7.2. Update reference ↗
CVE-2026-34600 19 May 2026 < 3.5.3 3.5.3. Update reference ↗
CVE-2025-57798 19 May 2026 < 3.7.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-22810 18 May 2026 < 3.5.7 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-27134 30 Apr 2025 < 3.3.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-27409 30 Apr 2025 < 3.3.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-25187 7 Feb 2025 < 3.1.24 3.1.24 Update reference ↗
CVE-2025-24028 7 Feb 2025 >= 3.2.6, < 3.2.12 3.2.12 Update reference ↗
CVE-2024-55630 7 Feb 2025 < 3.2.8 3.2.8 Update reference ↗
CVE-2024-53268 25 Nov 2024 < 3.0.3 3.0.3 Update reference ↗
CVE-2024-49362 14 Nov 2024 < 3.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-40643 9 Sep 2024 < 3.0.15 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-37898 21 Jun 2024 < 2.12.9 2.12.9 Update reference ↗
CVE-2023-38506 21 Jun 2024 < 2.12.10 2.12.10 Update reference ↗
CVE-2023-39517 21 Jun 2024 < 2.12.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-45673 21 Jun 2024 < 2.13.3 2.13.3. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.