High severity7.5NVD Advisory· Published Sep 9, 2026
CVE-2026-87807
CVE-2026-87807
Description
siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter. Attackers can inject UNION SELECT statements to read the entire blocks table, bypassing publish-access controls and exposing all document content and sensitive attributes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.8.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.