Typora

Typora

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.25%
  • Veröffentlicht 20.06.2023 15:15:10
  • Zuletzt bearbeitet 10.12.2024 17:15:06

Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 07.03.2023 20:15:09
  • Zuletzt bearbeitet 21.11.2024 07:38:16

A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached locally. The...

  • EPSS 0.08%
  • Veröffentlicht 23.12.2022 23:15:08
  • Zuletzt bearbeitet 15.04.2025 15:15:58

Cross Site Scripting (XSS) vulnerability in typora through 1.38 allows remote attackers to run arbitrary code via export from editor.

  • EPSS 0.54%
  • Veröffentlicht 07.12.2022 04:15:11
  • Zuletzt bearbeitet 23.04.2025 14:15:23

Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the file when opening a file with the affected product.

Exploit
  • EPSS 0.36%
  • Veröffentlicht 19.08.2021 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:08:46

Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration error in the mathematical formula blocks. This is a different vulnerability from CVE-2020-18221.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 26.05.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:08:29

Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during block rendering of a mathematical formula.

Exploit
  • EPSS 0.46%
  • Veröffentlicht 05.02.2021 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:08:45

An issue was discovered in Typora 0.9.67. There is an XSS vulnerability that causes Remote Code Execution.

  • EPSS 2.17%
  • Veröffentlicht 09.01.2020 23:15:10
  • Zuletzt bearbeitet 21.11.2024 04:38:19

A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerabi...

Exploit
  • EPSS 0.94%
  • Veröffentlicht 17.05.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:22:21

Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstrated by file:\\\ on macOS or Linux, or file://C| on Windows. This is different from CVE-2019-12137.

Exploit
  • EPSS 4.58%
  • Veröffentlicht 16.05.2019 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:22:17

Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.