Typora 0.9.8.7.2 Beta

CPE Details

Typora 0.9.8.7.2 Beta
0.9.8.7.2
2019-09-25 14:39 +00:00
2019-09-25 14:39 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:a:typora:typora:0.9.8.7.2:beta:*:*:*:*:*:*

Informations

Vendor

typora

Product

typora

Version

0.9.8.7.2

Update

beta

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-41481 2024-08-07 22:00 +00:00 Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.
6.1
MEDIUM
CVE-2024-41482 2024-08-07 22:00 +00:00 Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.
6.1
MEDIUM
CVE-2023-39703 2023-08-31 22:00 +00:00 A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via uploading a crafted Markdown file.
6.1
MEDIUM
CVE-2023-2971 2023-08-19 05:45 +00:00 Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora.
6.5
MEDIUM
CVE-2023-2317 2023-08-19 05:35 +00:00 DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora main window via loading typora://app/typemark/updater/update.html in tag. This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora.
9.6
CRITICAL
CVE-2023-2316 2023-08-19 05:34 +00:00 Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/". This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora.
7.4
HIGH
CVE-2023-1003 2023-02-24 07:53 +00:00 A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.8 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-221736.
7.8
HIGH
CVE-2022-40011 2022-12-22 23:00 +00:00 Cross Site Scripting (XSS) vulnerability in typora through 1.38 allows remote attackers to run arbitrary code via export from editor.
6.1
MEDIUM
CVE-2022-43668 2022-12-06 23:00 +00:00 Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the file when opening a file with the affected product.
6.1
MEDIUM
CVE-2019-7295 2022-10-03 14:19 +00:00 typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
6.1
MEDIUM
CVE-2019-7296 2022-10-03 14:19 +00:00 typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
6.1
MEDIUM
CVE-2020-18221 2021-05-26 12:50 +00:00 Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during block rendering of a mathematical formula.
6.1
MEDIUM
CVE-2019-20374 2020-01-09 21:40 +00:00 A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to improper HTML sanitization. Given that the application is based on the Electron framework, the XSS leads to remote code execution in an unsandboxed environment.
9.6
CRITICAL
CVE-2019-6803 2019-01-25 04:00 +00:00 typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.
6.1
MEDIUM
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.