CVE-2026-82805
- EPSS 0.28%
- Veröffentlicht 31.08.2026 15:45:07
- Zuletzt bearbeitet 31.08.2026 20:56:08
A vulnerability was found in Typora up to 1.13.8/1.14.6. This vulnerability affects unknown code of the component Mermaid Rendering Engine. The manipulation of the argument classDef/style results in cross site scripting. The attack may be launched re...
CVE-2024-14010
- EPSS 1.17%
- Veröffentlicht 12.12.2025 19:55:03
- Zuletzt bearbeitet 30.09.2026 18:17:56
Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve ...
CVE-2024-41482
- EPSS 0.34%
- Veröffentlicht 12.08.2024 13:38:31
- Zuletzt bearbeitet 25.03.2025 17:16:04
Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.
CVE-2024-41481
- EPSS 0.41%
- Veröffentlicht 12.08.2024 13:38:30
- Zuletzt bearbeitet 20.03.2025 14:15:19
Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.
CVE-2024-33300
- EPSS 0.55%
- Veröffentlicht 01.05.2024 19:15:26
- Zuletzt bearbeitet 10.06.2025 18:07:52
Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrary code by uploading Markdown files.
CVE-2024-31784
- EPSS 0.26%
- Veröffentlicht 16.04.2024 04:15:09
- Zuletzt bearbeitet 10.06.2025 01:14:55
An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the src component.
CVE-2024-31783
- EPSS 0.39%
- Veröffentlicht 16.04.2024 04:15:09
- Zuletzt bearbeitet 10.06.2025 01:19:10
Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted script during markdown file creation.
CVE-2020-18336
- EPSS 0.57%
- Veröffentlicht 10.10.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 05:08:32
Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file exporting function.
CVE-2023-39703
- EPSS 0.46%
- Veröffentlicht 01.09.2023 13:15:08
- Zuletzt bearbeitet 21.11.2024 08:15:50
A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via uploading a crafted Markdown file.
CVE-2023-2971
- EPSS 0.49%
- Veröffentlicht 19.08.2023 06:15:47
- Zuletzt bearbeitet 21.11.2024 07:59:40
Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malici...