Typora

Typora

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 12.08.2024 13:38:31
  • Zuletzt bearbeitet 25.03.2025 17:16:04

Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.

  • EPSS 0.16%
  • Veröffentlicht 12.08.2024 13:38:30
  • Zuletzt bearbeitet 20.03.2025 14:15:19

Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 01.05.2024 19:15:26
  • Zuletzt bearbeitet 10.06.2025 18:07:52

Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrary code by uploading Markdown files.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 16.04.2024 04:15:09
  • Zuletzt bearbeitet 10.06.2025 01:14:55

An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the src component.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 16.04.2024 04:15:09
  • Zuletzt bearbeitet 10.06.2025 01:19:10

Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted script during markdown file creation.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 10.10.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 05:08:32

Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file exporting function.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 01.09.2023 13:15:08
  • Zuletzt bearbeitet 21.11.2024 08:15:50

A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via uploading a crafted Markdown file.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 19.08.2023 06:15:47
  • Zuletzt bearbeitet 21.11.2024 07:59:40

Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malici...

Exploit
  • EPSS 49.28%
  • Veröffentlicht 19.08.2023 06:15:46
  • Zuletzt bearbeitet 21.11.2024 07:58:22

DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora main window via loading typora://app/typemark/updater/update.html in <embed> tag...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 19.08.2023 06:15:46
  • Zuletzt bearbeitet 21.11.2024 07:58:22

Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absolute-path>". This vulnerability can be exploited if a user opens a ma...