Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.78% | — | B3log SiyuanAI | 24/6/2026 | 25/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This vulnerability is fixed in 3.7.0. | |
| Aplazada | Crítica (9.4) | 0.70% | — | B3log SiyuanAI | 21/6/2026 | 24/6/2026 | SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or… | |
| Rechazada | Sin puntuar | — | — | B3log SiyuanAI | 21/6/2026 | 17/9/2026 | Rejected reason: This record is a duplicate; use CVE-2026-56397 instead. | |
| Aplazada | Crítica (9) | 0.41% | — | B3log SiyuanAI | 14/5/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version fields of a package's plugin.json (and the equivalent theme.json / template.json / widget.json / icon.json) into the Settings → Marketplace UI without HTML escaping. The… | |
| Aplazada | Alta (7.2) | 0.35% | — | B3log SiyuanAI | 14/5/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs. POST /api/graph/getGraph, POST /api/graph/getLocalGraph, POST /api/sync/setSyncInterval, POST /api/storage/updateRecentDocViewTime, POST… | |
| Aplazada | Media (4.3) | 0.27% | — | B3log SiyuanAI | 14/5/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset, searchTag, searchWidget, and searchTemplate publish-mode Readers can enumerate metadata from documents that are invisible to the publish service. This vulnerability is fixed in 3.7.0. | |
| Aplazada | Media (4.3) | 0.25% | — | B3log SiyuanAI | 14/5/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly, despite the handler performing a configuration write that is normally guarded by both. Any authenticated user —… | |
| Aplazada | Crítica (9.4) | 0.55% | — | B3log SiyuanAI | 14/5/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw strings.ReplaceAll(tpl, "${avName}", nodeAvName) to embed the name in HTML before pushing to all clients via WebSocket. Three… | |
| Aplazada | Crítica (9.4) | 0.55% | — | B3log SiyuanAI | 14/5/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/block/popover.ts reads aria-label via getAttribute and passes it through decodeURIComponent before assigning to messageElement.innerHTML in app/src/dialog/tooltip.ts:41. The encoder used at the… | |
| Aplazada | Alta (8.3) | 0.43% | — | B3log SiyuanAI | 14/5/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron windows are created with… | |
| Aplazada | Alta (7.1) | 0.46% | — | B3log SiyuanAI | 24/4/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePath) but did not address the root cause — a redundant url.PathUnescape() call in serveExport(). An authenticated attacker can use double URL encoding (%252e%252e) to… | |
| Aplazada | Alta (8.8) | 0.20% | — | B3log SiyuanAI | 24/4/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Electron renderer. The notification route POST /api/notification/pushMsg accepts a user-controlled msg value, forwards it through the backend broadcast layer, and the… | |
| Modificada | Media (5.3) | 0.38% | — | B3log Siyuan | 17/4/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in bazaar README rendering (incomplete fix for CVE-2026-33066) enabled the Lute HTML sanitizer, but the sanitizer does not block iframe tags, and its URL-prefix blocklist does not effectively filter… | |
| Analizada | Crítica (9) | 0.53% | — | B3log Siyuan | 16/4/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. This allows attacker-controlled javascript: URLs in Mermaid code blocks to survive into the rendered… | |
| Analizada | Alta (8.5) | 0.44% | — | B3log Siyuan | 16/4/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequences such as ../… | |
| Analizada | Alta (8.1) | 0.54% | — | B3log Siyuan | 16/4/2026 | 17/6/2026 | SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttributeView endpoint is protected only by generic authentication that accepts publish-service RoleReader tokens. The handler passes a caller-controlled id directly to a model function that… | |
| Analizada | Alta (8.7) | 0.45% | — | B3log Siyuan | 9/4/2026 | 17/6/2026 | SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In this mode, <img> tags with src attributes survive Mermaid's internal DOMPurify and land in SVG <foreignObject> blocks. The SVG is injected via innerHTML with no secondary… | |
| Analizada | Crítica (9) | 0.65% | — | B3log Siyuan | 7/4/2026 | 20/7/2026 | SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creating a stored XSS… | |
| Analizada | Alta (8.6) | 0.60% | 💥 Exploit | B3log Siyuan | 31/3/2026 | 17/6/2026 | SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the SanitizeSVG function introduced in version 3.6.0 to fix XSS in the unauthenticated /api/icon/getDynamicIcon endpoint can be bypassed by using namespace-prefixed element names such as <x:script… | |
| Analizada | Alta (8.2) | 0.36% | — | B3log Siyuan | 31/3/2026 | 17/6/2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is mixed with raw special characters. An attacker can embed a malicious IAL value inside a .sy document, package it as a .sy.zip,… | |
| Analizada | Alta (7.5) | 1.5% | 💥 Exploit | B3log Siyuan | 31/3/2026 | 24/7/2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, /api/bookmark/getBookmark filters bookmark results by calling FilterBlocksByPublishAccess(nil, ...). Because… | |
| Analizada | Crítica (9.6) | 0.80% | — | B3log Siyuan | 31/3/2026 | 24/7/2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * + Access-Control-Allow-Private-Network: true) to inject a JavaScript snippet via… | |
| Analizada | Crítica (9) | 0.73% | — | B3log Siyuan | 31/3/2026 | 24/7/2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with “Cover From -> Asset Field” enabled. The vulnerable code accepts arbitrary http(s) URLs without… | |
| Analizada | Alta (7.5) | 0.62% | — | B3log Siyuan | 26/3/2026 | 17/6/2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue. | |
| Analizada | Alta (7.5) | 0.52% | — | B3log Siyuan | 26/3/2026 | 17/6/2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. Version 3.6.2 patches the issue. |