Patch & vulnerability status
Evernote 11.28.2
Latest tracked version 11.28.2. Release status, tracked CVEs, and automated cross-platform patching for Evernote.
| Platform | Latest version | CVEs tracked | Last checked |
|---|---|---|---|
| Linux | 11.28.2 | 0 | 2026-08-10 |
| Mac | 11.28.2 | 0 | 2026-08-10 |
| Windows | 11.28.2 | 10 | 2026-08-10 |
Known vulnerabilities (CVEs) in Evernote
Lavawall tracks 10 published CVEs affecting Evernote, and deploys the versions that fix them automatically across your fleet.
| CVE | Published | Severity | Details | Vector |
|---|---|---|---|---|
| CVE-2023-50643 | 2024-01-09 01:15:39 | CRITICAL (10) | An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components. | NETWORK |
| CVE-2020-17759 | 2021-06-24 20:15:09 | HIGH (9) | An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941. | NETWORK |
| CVE-2019-17051 | 2019-09-30 20:15:11 | HIGH (8) | Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop operation on a crafted Terminal file. | LOCAL |
| CVE-2019-10038 | 2019-05-31 22:29:01 | MEDIUM (4) | Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.app/Contents/MacOS/Calculator file. | LOCAL |
| CVE-2018-20351 | 2018-12-22 00:29:00 | MEDIUM (4) | The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832. | NETWORK |
| CVE-2018-20058 | 2018-12-11 09:29:00 | MEDIUM (5) | In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-28634. | NETWORK |
| CVE-2018-18524 | 2019-05-13 14:29:01 | MEDIUM (4) | Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the attacker can read the victim's files and achieve remote execution command on the victim's computer. | NETWORK |
| CVE-2016-4900 | 2017-05-22 16:29:00 | MEDIUM (7) | Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory. | NETWORK |
| CVE-2013-5116 | 2020-01-31 15:15:11 | HIGH (7) | Evernote prior to 5.5.1 has insecure password change | LOCAL |
| CVE-2013-5112 | 2020-01-31 14:15:11 | MEDIUM (5) | Evernote before 5.5.1 has insecure PIN storage | PHYSICAL |
Why keeping Evernote patched matters
Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Evernote release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.
How Lavawall® patches Evernote
Lavawall® watches Evernote releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Evernote, one policy to bring them current, and timestamped evidence for audits.
Frequently asked questions
Lavawall tracks Evernote at version 11.28.2 (last checked 2026-08-10). New releases are monitored continuously and can be deployed automatically across your fleet.
Lavawall continuously monitors Evernote for newly disclosed CVEs and remediates them automatically as they appear.
Deploy the Lavawall® agent and Evernote updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.
Lavawall® monitors releases and CVEs for Evernote through public information and proprietary statistical analysis, and can patch it automatically across your fleet.