b3log has 3 CVEs on record. The busiest recent month was March 2026 with 3. The median CVSS is 9.0 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.0
- Publish → KEV
- —
- Last 90 days
- 0 prev 3
b3log vulnerabilities
CVEs affecting b3log, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-34453High· 7.5PoCSiYuan is a personal knowledge management system
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, /api/bookmark/getBookmark f…
CVE-2026-34449Critical· 9.6SiYuan is a personal knowledge management system
SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * …
CVE-2026-34448Critical· 9.0SiYuan is a personal knowledge management system
SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with “Cover From -…