CVE-2026-105785Medium· 4.8▾ SunlitJoplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and passwor…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 26.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts allows UserModel.resetPassword to accept any token returned by TokenModel.userFromToken. An attacker who obtains a victim's CSRF or confirmation token through a separate disclosure channel can submit it to the public password-reset endpoint, replace the victim's password, and cause the existing sessions and API applications to be deleted. This issue is fixed in Joplin Server 3.7.2.
joplin < 3.7.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105784Medium· 4.6Joplin whiteboard card rendering allows CSS injection into application chrome
CVE-2026-105783High· 8.0Joplin Web Clipper pairing allows cross-origin theft of a permanent API token
CVE-2026-105786High· 8.5Joplin: Unauthenticated account takeover via an attacker-chosen application-authorisation identifier
CVE-2026-55210High· 7.4Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-59814High· 7.6Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-59815Medium· 4.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks