Total vulnerabilities in the database
Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR.
CVSS v3:
CWEs:
OWASP TOP 10: