VYPR

Siyuan

by Siyuan Note

Source repositories

CVEs (214)

  • CVE-2026-93921MedSep 19, 2026
    risk 0.21cvss 4.3epss 0.00

    SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block titles, names, aliases, and…

  • CVE-2026-86191MedSep 5, 2026
    risk 0.21cvss 4.3epss 0.00

    SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint…

  • CVE-2026-85579MedSep 4, 2026
    risk 0.21cvss 4.3epss 0.00

    SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global undo-log stack for a caller-supplied root ID…

  • CVE-2026-45148MedMay 14, 2026
    risk 0.21cvss 4.3epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset, searchTag, searchWidget, and searchTemplate publish-mode Readers can enumerate metadata from documents that are invisible to the publish service. This…

  • CVE-2026-45147MedMay 14, 2026
    risk 0.21cvss 4.3epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly, despite the handler performing a configuration write that is normally guarded…

  • CVE-2026-66394HigJul 27, 2026
    risk 0.00cvss 8.7epss 0.00

    SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements…

  • CVE-2026-65607MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.01

    SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main export branch, this branch joins the raw, percent-decoded request path with util.TempDir and serves the…

  • CVE-2026-59855HigJul 9, 2026
    risk 0.00cvss —epss 0.01

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts interpolates the unsanitized this.path value into HTML assigned to innerHTML, allowing a crafted asset link containing a double quote to break out of the src…

  • CVE-2026-59854MedJul 9, 2026
    risk 0.00cvss 4.9epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles accepts attacker-supplied absolute source paths and relies on util.IsSensitivePath in kernel/util/path.go, whose denylist misses common home-directory credential files…

  • CVE-2026-59853MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used by sibling storage endpoints, allowing a publish-mode…

  • CVE-2026-59833HigJul 9, 2026
    risk 0.00cvss —epss 0.01

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, but Lute's dangerous javascript scheme block does not check form action or SVG xlink:href attributes,…

  • CVE-2026-56395Jun 21, 2026
    risk 0.00cvss —epss 0.01

    Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.

  • CVE-2026-25647MedFeb 6, 2026
    risk 0.00cvss 4.6epss 0.00

    Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has a Stored Cross-Site Scripting (XSS) vulnerability in the Markdown rendering engine. An attacker can inject malicious JavaScript into a Markdown text/note.…

  • CVE-2026-23852CriJan 19, 2026
    risk 0.00cvss 9.6epss 0.01

    SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attacker to inject arbitrary HTML attributes into the `icon` attribute of a block via the `/api/attr/setBlockAttrs` API. The payload is…

Page 11 of 11