CVE-2026-55179Medium· 6.5▾ SunlitJoplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in packages/server/src/routes/index/items.ts loads item content from a…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in packages/server/src/routes/index/items.ts loads item content from an attacker-supplied internal server ID without checking whether the signed-in user owns or can access that item. Any authenticated user who obtains or guesses another user's item ID can read the corresponding note or item content when end-to-end encryption does not protect it. This issue is fixed in version 3.7.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55210High· 7.4Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-59814High· 7.6Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-59815Medium· 4.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-46650Medium· 4.4Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-55105High· 7.7Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-59816Medium· 4.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks