VYPR

Siyuan

by Siyuan Note

Source repositories

CVEs (130)

  • CVE-2026-65606CriJul 23, 2026
    risk 0.00cvss 9.6epss 0.01

    SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/ link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab…

  • CVE-2026-65605CriJul 23, 2026
    risk 0.00cvss 9.6epss 0.01

    SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true;…

  • CVE-2026-59855HigJul 9, 2026
    risk 0.00cvss epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts interpolates the unsanitized this.path value into HTML assigned to innerHTML, allowing a crafted asset link containing a double quote to break out of the src…

  • CVE-2026-59854MedJul 9, 2026
    risk 0.00cvss 4.9epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles accepts attacker-supplied absolute source paths and relies on util.IsSensitivePath in kernel/util/path.go, whose denylist misses common home-directory credential files…

  • CVE-2026-59853MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used by sibling storage endpoints, allowing a publish-mode…

  • CVE-2026-59834HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used by non-SQL search modes, allowing an unauthenticated publish…

  • CVE-2026-59833HigJul 9, 2026
    risk 0.00cvss epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, but Lute's dangerous javascript scheme block does not check form action or SVG xlink:href attributes,…

  • CVE-2026-59832HigJul 9, 2026
    risk 0.00cvss 7.7epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath containment or sensitive-path checks,…

  • CVE-2026-25647MedFeb 6, 2026
    risk 0.00cvss 4.6epss 0.00

    Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has a Stored Cross-Site Scripting (XSS) vulnerability in the Markdown rendering engine. An attacker can inject malicious JavaScript into a Markdown text/note.…

  • CVE-2026-23852CriJan 19, 2026
    risk 0.00cvss 9.6epss 0.01

    SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attacker to inject arbitrary HTML attributes into the `icon` attribute of a block via the `/api/attr/setBlockAttrs` API. The payload is…

Page 7 of 7