CVE-2026-56395Medium▾ SunlitRejected reason: This record is a duplicate; use CVE-2026-56397 instead.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
0.4% → 0.7%
Last analysed / modified upstream
Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/siyuan-note/siyuan/kernel <= 0.0.0-20260313024916-fd6526133bb3Connected by shared product, vendor, weakness, or advisory.
GHSA-24r3-p3x6-cqvxCritical· 9.6Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
CVE-2026-56397MediumSiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
GHSA-57v5-wqx3-cgj4Medium· 5.8SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAt…
CVE-2026-72790Medium· 5.8SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /ap…
CVE-2026-72799Medium· 5.8SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
CVE-2026-72794High· 8.6SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf