CVE-2026-105784 | laurent22 Joplin up to 3.7.12 WhiteboardEditor TextNode.tsx dangerouslySetInnerHTML cross site scripting
A vulnerability has been found in laurent22 Joplin up to 3.7.12 and classified as problematic. This issue affects the function dangerouslySetInnerHTML of the file packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/TextNode.tsx of the component WhiteboardEditor. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2026-105784. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More