Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.42% | — | B3log SiyuanAI | 3/8/2026 | 26/8/2026 | SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a heading block… | |
| Aplazada | Crítica (9.2) | 0.41% | — | B3log SiyuanAI | 3/8/2026 | 26/8/2026 | SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not.… | |
| Aplazada | Media (6.9) | 0.33% | — | B3log SiyuanAI | 3/8/2026 | 26/8/2026 | SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the… | |
| Aplazada | Crítica (9.2) | 0.53% | — | B3log SiyuanAI | 3/8/2026 | 26/8/2026 | SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of… | |
| Aplazada | Crítica (9.3) | 0.54% | — | B3log SiyuanAI | 27/7/2026 | 17/9/2026 | SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary code in the Electron… | |
| Aplazada | Crítica (9.4) | 0.56% | — | Siyuan DesktopAI | 27/7/2026 | 17/9/2026 | SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access… | |
| Aplazada | Crítica (9.3) | 0.47% | — | B3log SiyuanAI | 27/7/2026 | 28/7/2026 | SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements which the HTML parser treats as raw text… | |
| Aplazada | Crítica (10) | 0.76% | 💥 PoC | B3log SiyuanAI | 25/7/2026 | 17/9/2026 | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the… | |
| Aplazada | Alta (7.1) | 0.59% | — | B3log SiyuanAI | 23/7/2026 | 27/7/2026 | SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main export branch, this branch joins the raw, percent-decoded request path with util.TempDir and serves the file without the IsSubPath or… | |
| Aplazada | Crítica (9.4) | 0.79% | — | B3log SiyuanAI | 23/7/2026 | 17/9/2026 | SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab header via innerHTML without escaping it… | |
| Aplazada | Crítica (9.4) | 0.79% | — | B3log SiyuanAI | 23/7/2026 | 17/9/2026 | SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true; because balanced self-closing tags such as… | |
| Aplazada | Alta (8.6) | 0.53% | — | B3log SiyuanAI | 9/7/2026 | 14/7/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts interpolates the unsanitized this.path value into HTML assigned to innerHTML, allowing a crafted asset link containing a double quote to break out of the src attribute, inject an event handler, and… | |
| Aplazada | Media (4.9) | 0.48% | — | B3log SiyuanAI | 9/7/2026 | 10/7/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles accepts attacker-supplied absolute source paths and relies on util.IsSensitivePath in kernel/util/path.go, whose denylist misses common home-directory credential files such as .git-credentials, .netrc,… | |
| Aplazada | Media (6.5) | 0.40% | — | B3log SiyuanAI | 9/7/2026 | 10/7/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used by sibling storage endpoints, allowing a publish-mode Reader to read private document paths,… | |
| Aplazada | Alta (7.5) | 0.51% | — | B3log SiyuanAI | 9/7/2026 | 10/7/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used by non-SQL search modes, allowing an unauthenticated publish visitor to inject a UNION SELECT and return… | |
| Aplazada | Alta (8.6) | 0.53% | — | LuteAIB3log SiyuanAI | 9/7/2026 | 10/7/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, but Lute's dangerous javascript scheme block does not check form action or SVG xlink:href attributes, allowing stored cross-site scripting in… | |
| Aplazada | Alta (7.7) | 0.46% | — | B3log SiyuanAI | 9/7/2026 | 10/7/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath containment or sensitive-path checks, allowing an authenticated request such as… | |
| Aplazada | Crítica (9) | 0.62% | — | B3log SiyuanAI | 24/6/2026 | 25/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are serialized into the data-obj HTML attribute of each marketplace card. Because the attribute is single-quoted and the value is produced with… | |
| Aplazada | Alta (8.7) | 0.44% | — | LuteAIB3log SiyuanAI | 24/6/2026 | 25/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, Lute's HTML sanitizer does not remove <iframe> elements. Combined with the SiYuan Electron client's permissive security configuration, an attacker can include a malicious <iframe> in a Bazaar package README that executes arbitrary commands… | |
| Aplazada | Crítica (9.9) | 0.51% | — | B3log SiyuanAI | 24/6/2026 | 26/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, url, phone, and mAsset. A cell value like </textarea><img src=x onerror="..."> or "><img src=x onerror="..."> breaks out… | |
| Aplazada | Alta (7.1) | 0.30% | — | B3log SiyuanAI | 24/6/2026 | 26/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/readme.go renders a Bazaar package README from Markdown to HTML with the lute engine and SetSanitize(true). The lute sanitizer is an event-handler blocklist: allowAttr rejects only attribute names… | |
| Aplazada | Crítica (9.2) | 0.58% | 💥 Exploit | B3log SiyuanAI | 24/6/2026 | 25/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server unconditionally trusts all chrome-extension:// origins, granting RoleAdministrator access to every installed browser extension without any authentication. Combined with the default empty AccessAuthCode on… | |
| Aplazada | Media (5.9) | 0.38% | — | B3log SiyuanAI | 24/6/2026 | 25/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from authentication in SiYuan's kernel router (router.go, "不需要鉴权" -- no auth needed). When called with type=8 and a valid block id parameter, this endpoint invokes… | |
| Aplazada | Crítica (9.9) | 0.54% | — | B3log SiyuanAI | 24/6/2026 | 25/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSnippet() interpolates it via insertAdjacentHTML. A payload like runs arbitrary JavaScript in the renderer. On Electron desktop builds the renderer… | |
| Aplazada | Alta (7.5) | 2.4% | 💥 Exploit | B3log SiyuanAI | 24/6/2026 | 25/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the /export/ route but the identical root cause remains in the /assets/*path route. In publish mode (anonymous read-only HTTP endpoint, default port 6808), an… |