Note-Mark
Enchant97 · 10 CVEs
Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)
Sep 4, 2026
Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in note-mark
Sep 3, 2026
Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leading to Remote Code Execution
May 14, 2026
Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
May 14, 2026
Note Mark: Unauthenticated read of notes and assets in soft-deleted public books
May 4, 2026
Note Mark: OIDC-registered users authenticated by submitting password "null"
May 4, 2026
Note Mark has Broken Access Control on Asset Download
Apr 16, 2026
Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel
Apr 16, 2026
Note Mark has Stored XSS via Unrestricted Asset Upload
Apr 16, 2026
Note Mark has a stored XSS in the note link href attribute
Jul 29, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-50553 | Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) | HIGH | 0.46% | Sep 4, 2026 |
| CVE-2026-50554 | Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in note-mark | MEDIUM | 0.42% | Sep 3, 2026 |
| CVE-2026-44522 | Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leading to Remote Code Execution | HIGH | 0.72% | May 14, 2026 |
| CVE-2026-44523 | Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery | CRITICAL | 0.16% | May 14, 2026 |
| CVE-2026-41572 | Note Mark: Unauthenticated read of notes and assets in soft-deleted public books | MEDIUM | 0.33% | May 4, 2026 |
| CVE-2026-41571 | Note Mark: OIDC-registered users authenticated by submitting password "null" | CRITICAL | 0.48% | May 4, 2026 |
| CVE-2026-40265 | Note Mark has Broken Access Control on Asset Download | MEDIUM | 0.50% | Apr 16, 2026 |
| CVE-2026-40263 | Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel | LOW | 0.31% | Apr 16, 2026 |
| CVE-2026-40262 | Note Mark has Stored XSS via Unrestricted Asset Upload | HIGH | 0.42% | Apr 16, 2026 |
| CVE-2024-41819 | Note Mark has a stored XSS in the note link href attribute | HIGH | 0.82% | Jul 29, 2024 |
Showing 1 to 10 of 10 CVEs