Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.82% | — | B3log SiyuanAI | 17/9/2026 | 17/9/2026 | SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with unescaped HTML in bookmark attributes that execute scripts in the Electron renderer with access to child_process for command execution. | |
| Aplazada | Alta (8.4) | 0.48% | — | B3log SiyuanAI | 9/9/2026 | 14/9/2026 | SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory. | |
| Aplazada | Alta (8.4) | 0.37% | — | B3log SiyuanAI | 9/9/2026 | 9/9/2026 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping. Authenticated attackers can craft asset filenames containing malicious markup that executes JavaScript in the victim's browser when searching… | |
| Aplazada | Alta (7.4) | 0.36% | — | B3log SiyuanAI | 9/9/2026 | 10/9/2026 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject malicious URLs with event handlers that execute JavaScript in the authenticated SiYuan origin when users… | |
| Aplazada | Alta (8.4) | 0.37% | — | B3log SiyuanAI | 9/9/2026 | 9/9/2026 | SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding. Attackers can craft malicious template paths that break out of the attribute context and execute JavaScript when a victim opens notebook configuration, enabling same-origin API requests… | |
| Aplazada | Media (6.9) | 0.34% | — | B3log SiyuanAI | 9/9/2026 | 14/9/2026 | Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers can submit arbitrary search terms to learn whether matching content exists in… | |
| Aplazada | Alta (8.7) | 0.44% | — | B3log SiyuanAI | 9/9/2026 | 9/9/2026 | SiYuan versions <= 3.8.1 contain an incomplete fix for CVE-2026-32767 (GHSA-j7wh-x834-p3r7). The prior fix (commit d5e2d0bc) added an administrator check for SQL mode (method=2) in POST /api/search/fullTextSearchBlock, but the endpoint still does not enforce the application's read-only boundary: for method=2 it… | |
| Aplazada | Alta (8.7) | 0.45% | — | B3log SiyuanAI | 9/9/2026 | 10/9/2026 | siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter. Attackers can inject UNION SELECT statements to read the entire blocks table, bypassing publish-access controls and exposing all document content and sensitive attributes. | |
| Aplazada | Alta (8.4) | 0.37% | — | B3log SiyuanAI | 9/9/2026 | 18/9/2026 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted text assets in a workspace can execute JavaScript in the SiYuan origin when victims… | |
| Aplazada | Alta (7.1) | 0.35% | — | B3log SiyuanAI | 9/9/2026 | 18/9/2026 | Siyuan before v3.8.2 fails to apply publish-access filtering to embedded blocks before rendering in the /api/export/preview and /api/lute/copyStdMarkdown endpoints. Attackers with reader access can retrieve the full rendered content of private, hidden, or publish-disabled blocks by accessing public documents… | |
| Aplazada | Alta (8.6) | 0.71% | — | B3log SiyuanAI | 8/9/2026 | 10/9/2026 | SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that write to the clipboard, and when pasted into SiYuan, injected scripts execute with… | |
| Aplazada | Alta (7.1) | 0.35% | — | B3log SiyuanAI | 5/9/2026 | 10/9/2026 | SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization. | |
| Aplazada | Media (5.3) | 0.28% | — | B3log SiyuanAI | 5/9/2026 | 8/9/2026 | SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint to retrieve complete key schemas… | |
| Aplazada | Alta (8.7) | 0.51% | — | B3log SiyuanAI | 4/9/2026 | 8/9/2026 | SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path without eviction. Unauthenticated attackers can send numerous unique request paths to permanently increase process memory and synchronization… | |
| Aplazada | Alta (8.7) | 0.59% | — | B3log SiyuanAI | 4/9/2026 | 8/9/2026 | SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing capacity limits or eviction policies. Unauthenticated attackers can submit repeated authentication requests with… | |
| Aplazada | Alta (7.1) | 0.64% | — | B3log SiyuanAI | 4/9/2026 | 14/9/2026 | SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader role can request a logical asset under data/assets/ that is a symlink to a file outside the workspace and receive the target… | |
| Aplazada | Alta (7.1) | 0.44% | — | B3log SiyuanAI | 4/9/2026 | 8/9/2026 | SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can repeatedly authenticate with valid credentials to create persistent session entries without expiry or capacity limits, causing… | |
| Aplazada | Alta (8.7) | 0.57% | — | B3log SiyuanAI | 4/9/2026 | 10/9/2026 | SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send repeated requests with unique identifiers to exhaust process memory and degrade… | |
| Aplazada | Alta (7.1) | 0.58% | — | B3log SiyuanAI | 4/9/2026 | 8/9/2026 | SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publishAccess.json file by requesting case-variant paths like PublishAccess.json to disclose sensitive publish-access… | |
| Aplazada | Media (5.3) | 0.28% | — | B3log SiyuanAI | 4/9/2026 | 8/9/2026 | SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global undo-log stack for a caller-supplied root ID without applying publish-access… | |
| Aplazada | Alta (7.1) | 0.38% | — | B3log SiyuanAI | 4/9/2026 | 14/9/2026 | SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by… | |
| Aplazada | Alta (8.7) | 0.33% | — | B3log SiyuanAI | 3/9/2026 | 8/9/2026 | SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem) or CA private key (conf/ca.key) stored in the same conf/ directory.… | |
| Aplazada | Alta (8.7) | 0.51% | — | B3log SiyuanAI | 3/9/2026 | 8/9/2026 | SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access. | |
| Aplazada | Alta (8.6) | 0.43% | — | B3log SiyuanAI | 2/9/2026 | 2/9/2026 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and execute JavaScript to… | |
| Aplazada | Crítica (9.3) | 0.37% | — | B3log SiyuanAI | 30/8/2026 | 1/9/2026 | SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block. |