B3log
B3log Siyuan: vulnerabilidades y CVE
B3log Siyuan tiene 212 vulnerabilidades publicadas, 201 de ellas en los últimos 12 meses. 57 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE212
Últimos 12 meses201
Críticas57
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-104410 | Alta (8.7) | — | — | 2 oct 2026 | SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request… |
| CVE-2026-103763 | Media (6.9) | — | — | 2 oct 2026 | SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded documents through the getNotebookInfo endpoint. Attackers, including… |
| CVE-2026-103762 | Media (6.9) | — | — | 2 oct 2026 | SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished… |
| CVE-2026-101092 | Media (6.9) | 0.24% | — | 28 sept 2026 | SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can call the endpoint… |
| CVE-2026-101091 | Alta (7.1) | 0.26% | — | 28 sept 2026 | SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute… |
| CVE-2026-100646 | Alta (8.6) | 0.19% | — | 26 sept 2026 | SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in… |
| CVE-2026-100645 | Alta (8.6) | 0.35% | — | 26 sept 2026 | SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop… |
| CVE-2026-100644 | Alta (8.7) | 0.34% | — | 26 sept 2026 | SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter is concatenated into SQL without escaping. Unauthenticated attackers on published sites with… |
| CVE-2026-100643 | Alta (8.5) | 0.42% | — | 26 sept 2026 | SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources,… |
| CVE-2026-100642 | Alta (7.2) | 0.11% | — | 26 sept 2026 | SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating… |
| CVE-2026-100641 | Alta (8.6) | 0.53% | — | 26 sept 2026 | SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template… |
| CVE-2026-100640 | Alta (8.6) | 0.19% | — | 26 sept 2026 | SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderers to access native clipboard formats by invoking clipboardReadMathML, clipboardReadOffice, and… |
| CVE-2026-100639 | Alta (8.6) | 0.47% | — | 26 sept 2026 | SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts, assigned via innerHTML in app/src/protyle/gutter/index.ts) from content pasted as… |
| CVE-2026-100638 | Alta (8.3) | 0.47% | — | 26 sept 2026 | SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace… |
| CVE-2026-100637 | Alta (8.3) | 0.47% | — | 26 sept 2026 | SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID… |
| CVE-2026-100636 | Alta (8.3) | 0.54% | — | 26 sept 2026 | SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated administrators to write arbitrary HTML content to index.html outside the workspace… |
| CVE-2026-100635 | Alta (8.2) | 0.26% | — | 26 sept 2026 | SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without Secure or SameSite attributes over plaintext HTTP connections. An on-path attacker can… |
| CVE-2026-100634 | Media (5.3) | 0.47% | — | 26 sept 2026 | SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main process (app/electron/main.js). The handler ignores event.sender and forwards any… |
| CVE-2026-100633 | Alta (8.5) | 0.33% | — | 26 sept 2026 | SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensitive-path guard (util.IsForbiddenAbsPath(), invoked from resolvePath()) is applied only to the… |
| CVE-2026-93923 | Alta (8.6) | 0.60% | — | 18 sept 2026 | SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints… |
| CVE-2026-93922 | Alta (8.6) | 0.82% | — | 18 sept 2026 | SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads… |
| CVE-2026-93921 | Media (5.3) | 0.38% | — | 18 sept 2026 | SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted… |
| CVE-2026-93591 | Alta (7.2) | 0.32% | — | 18 sept 2026 | SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode… |
| CVE-2026-92986 | Alta (8.6) | 0.82% | — | 17 sept 2026 | SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or crafted notebooks to execute scripts in the… |
| CVE-2026-92985 | Alta (8.6) | 0.82% | — | 17 sept 2026 | SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with unescaped HTML in bookmark attributes… |
| CVE-2026-87815 | Alta (8.4) | 0.48% | — | 9 sept 2026 | SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal… |
| CVE-2026-87813 | Alta (8.4) | 0.37% | — | 9 sept 2026 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping. Authenticated attackers can craft asset… |
| CVE-2026-87812 | Alta (7.4) | 0.36% | — | 9 sept 2026 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject… |
| CVE-2026-87811 | Alta (8.4) | 0.37% | — | 9 sept 2026 | SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding. Attackers can craft malicious template paths that break out of the attribute context and… |
| CVE-2026-87810 | Media (6.9) | 0.34% | — | 9 sept 2026 | Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.