Known Vulnerabilities for SiYuan by SiYuan
Listed below are 10 of the newest known vulnerabilities associated with "SiYuan" by "SiYuan".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-69086 json | SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allo... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-69085 json | SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-suppli... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-69084 json | SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verb... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-69083 json | SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by u... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-68587 json | SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingL... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-68586 json | SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/ap... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-68585 json | SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that return... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-68584 json | SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoint... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-66396 json | SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover im... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-66395 json | SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that... | Not Provided | 2026-07-27 | 2026-07-28 |