MEDIUM
enchant97
CVE published 2026-09-03
CVE-2026-50554
CVE-2026-50554 is a vulnerability in Note Mark, an open-source note-taking application. The issue allows unauthenticated enumeration of soft-deleted notes from public books, potentially exposing sensitive metadata. This CVE was published on 2026-09-03T16:17:25.020Z and has not been modified since then. The vulnerability exists in the GET /api/books/{bookID}/notes endpoint, which accepts a 'deleted' query [truncated]