Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-78325

Опубликовано: 07 сент. 2026
Источник: nvd
EPSS Низкий

Описание

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.

EPSS

Процентиль: 0%
0.00088
Низкий

Дефекты

CWE-79

Связанные уязвимости

github
15 дней назад

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.

EPSS

Процентиль: 0%
0.00088
Низкий

Дефекты

CWE-79