VYPR

Siyuan

by Siyuan Note

Source repositories

CVEs (198)

  • CVE-2024-2692CriApr 4, 2024
    risk 0.59cvss 9.0epss 0.01

    SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.

  • CVE-2026-72811CriAug 14, 2026
    risk 0.58cvss 10.0epss 0.00

    SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while…

  • CVE-2026-69085CriAug 3, 2026
    risk 0.58cvss 10.0epss 0.01

    SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader…

  • CVE-2026-69084CriAug 3, 2026
    risk 0.58cvss 10.0epss 0.01

    SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. The endpoint is gated only by CheckAuth, making…

  • CVE-2026-69083CriAug 3, 2026
    risk 0.58cvss 10.0epss 0.00

    SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method…

  • CVE-2026-60084HigAug 22, 2026
    risk 0.57cvss 8.7epss 0.00

    SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute filesystem paths to recursively…

  • CVE-2026-74798HigAug 17, 2026
    risk 0.57cvss 8.7epss 0.00

    SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on the id parameter before passing it to RemoveUnusedAttributeView (kernel/model/attribute_view.go), which builds a filesystem path…

  • CVE-2026-54158CriJun 24, 2026
    risk 0.57cvss 9.9epss 0.01

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, url, phone, and mAsset. A cell value like …

  • CVE-2026-54067CriJun 24, 2026
    risk 0.57cvss 9.9epss 0.01

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing breaks out of its surrounding tag when renderSnippet() interpolates it via insertAdjacentHTML. A payload like runs arbitrary JavaScript in the renderer. On…

  • CVE-2026-50551CriJun 24, 2026
    risk 0.57cvss 9.9epss 0.01

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client.…

  • CVE-2026-33670CriMar 26, 2026
    risk 0.57cvss 9.8epss 0.01

    SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.

  • CVE-2026-33669CriMar 26, 2026
    risk 0.57cvss 9.8epss 0.01

    SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. Version 3.6.2 patches the issue.

  • CVE-2026-32938CriMar 20, 2026
    risk 0.57cvss 9.9epss 0.00

    SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed to by file:// links in pasted HTML into the workspace assets directory without validating paths against a sensitive-path list.…

  • CVE-2026-32767CriMar 20, 2026
    risk 0.57cvss 9.8epss 0.01

    SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextSearchBlock endpoint. When the method parameter is set to 2, the endpoint passes user-supplied input directly as a raw SQL…

  • CVE-2024-55660CriDec 12, 2024
    risk 0.57cvss 9.8epss 0.01

    SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access…

  • CVE-2026-75917HigAug 19, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (app/src/util/pathName.ts, getLeaf()/movePathTo()) used by the 'move/link to' path-selection dialogs, where document metadata fields (bookmark, alias, memo, and…

  • CVE-2026-75916HigAug 19, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. In genHintItemHTML() (app/src/protyle/hint/extend.ts), a candidate block's name, alias, and memo fields are concatenated into the popup's HTML without…

  • CVE-2026-74902HigAug 18, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via insertAdjacentHTML. Attackers can craft a malicious filename containing script payloads that execute with full…

  • CVE-2026-73608HigAug 13, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authorization vulnerability in the /api/av/getAttributeViewSearchTarget endpoint. The route is registered with CheckAuth only and performs…

  • CVE-2026-66396HigJul 27, 2026
    risk 0.55cvss 8.4epss 0.00

    SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that…

Page 2 of 10