VulnSea

siyuan-note has 78 CVEs on record. Disclosure cadence is accelerating: 73 in the last 90 days against 3 in the 90 before. The busiest recent month was September 2026 with 55. The median CVSS is 7.5 (high), with 14 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (23) and CWE-79 (20). Most affected products: github.com/siyuan-note/siyuan/kernel (53), siyuan (25).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
73 prev 3

Products

  • github.com/siyuan-note/siyuan/kernel 53
  • siyuan 25
78
Total CVEs
14
Critical
0
CISA KEV
0
Exploited

siyuan-note vulnerabilities

CVEs affecting siyuan-note, newest first. Open any entry for full detail, references, and exploit status.

78 CVEsRSS

CVE-2026-93922High· 8.8
2d ago

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that exec…

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via NVD
CVE-2026-93923High· 8.8PoC
2d ago

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject maliciou…

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.41%via NVD
CVE-2026-93921Medium· 4.3PoC
2d ago

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read bl…

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.23%via NVD
CVE-2026-93591High· 7.6PoC
3d ago

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous vis…

Midnightsiyuan-note · siyuanEPSS 0.29%via NVD
CVE-2026-92986High· 8.8
4d ago

SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters

SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or crafted notebooks to execute scripts in the Electron renderer …

Twilightsiyuan-note · siyuanEPSS 0.41%via NVD
CVE-2026-92985High· 8.8PoC
4d ago

SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree

SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with unescaped HTML in bookmark attributes that execute scrip…

Midnightsiyuan-note · siyuanEPSS 0.52%via NVD
CVE-2026-87810Medium· 5.3PoC
1w ago

Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock

Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers…

Twilightsiyuan-note · siyuanEPSS 0.21%via CVEORG
CVE-2026-87815High· 8.7PoC
1w ago

SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter

SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbit…

Midnightsiyuan-note · siyuanEPSS 0.27%via NVD
CVE-2026-87812Medium· 6.8
1w ago

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject malicious URLs with eve…

Sunlitsiyuan-note · siyuanEPSS 0.20%via NVD
CVE-2026-87807High· 7.5
1w ago

siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter

siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter. Attackers can inject UNION SELECT statements to read the entire blocks table, bypassing pu…

Twilightsiyuan-note · siyuanEPSS 0.27%via NVD
CVE-2026-87811High· 7.3PoC
1w ago

SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding

SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding. Attackers can craft malicious template paths that break out of the attribute context and execute JavaScrip…

Midnightsiyuan-note · siyuanEPSS 0.21%via NVD
CVE-2026-87813High· 7.3PoC
1w ago

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping. Authenticated attackers can craft asset filenames containing ma…

Midnightsiyuan-note · siyuanEPSS 0.26%via NVD
CVE-2026-87809Medium· 6.5
1w ago

Siyuan before v3.8.2 fails to apply publish-access filtering to embedded blocks before rendering in the /api/export/preview and /api/lute/copyStdMarkdown endpoints

Siyuan before v3.8.2 fails to apply publish-access filtering to embedded blocks before rendering in the /api/export/preview and /api/lute/copyStdMarkdown endpoints. Attackers with reader access can retrieve the full rendered content of p…

Sunlitsiyuan-note · siyuanEPSS 0.21%via NVD
CVE-2026-87808Medium· 4.9PoC
1w ago

SiYuan versions <= 3.8.1 contain an incomplete fix for CVE-2026-32767 (GHSA-j7wh-x834-p3r7)

SiYuan versions <= 3.8.1 contain an incomplete fix for CVE-2026-32767 (GHSA-j7wh-x834-p3r7). The prior fix (commit d5e2d0bc) added an administrator check for SQL mode (method=2) in POST /api/search/fullTextSearchBlock, but the endpoint s…

Twilightsiyuan-note · siyuanEPSS 0.32%via NVD
CVE-2026-87814High· 7.3
1w ago

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted te…

Twilightsiyuan-note · siyuanEPSS 0.21%via NVD
GHSA-57v5-wqx3-cgj4Medium· 5.8
1w ago

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAt…

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelvia OSV
CVE-2026-72790Medium· 5.8
1w ago

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /ap…

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via OSV
CVE-2026-86712High· 8.8
1w ago

SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer

SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that writ…

Twilightsiyuan-note · siyuanEPSS 0.38%via NVD
CVE-2026-86192Medium· 6.5
2w ago

SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint

SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing pri…

Sunlitsiyuan-note · siyuanEPSS 0.21%via NVD
CVE-2026-86191Medium· 4.3PoC
2w ago

SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visi…

SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visi…

Twilightsiyuan-note · siyuanEPSS 0.17%via NVD
CVE-2026-85583Medium· 6.5
2w ago

SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths

SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader role can request a logical asset under data…

Sunlitsiyuan-note · siyuanEPSS 0.48%via NVD
CVE-2026-85581High· 7.5
2w ago

SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication

SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send…

Twilightsiyuan-note · siyuanEPSS 0.32%via NVD
CVE-2026-85578Medium· 6.5
2w ago

SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false

SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access priv…

Sunlitsiyuan-note · siyuanEPSS 0.27%via NVD
CVE-2026-85584High· 7.5PoC
2w ago

SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing capacity limits or eviction policie…

SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing capacity limits or eviction policie…

Midnightsiyuan-note · siyuanEPSS 0.33%via NVD
CVE-2026-85579Medium· 4.3PoC
2w ago

SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint

SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global und…

Twilightsiyuan-note · siyuanEPSS 0.20%via NVD
CVE-2026-72799Medium· 5.8
2w ago

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via OSV
CVE-2026-72798High· 8.6
2w ago

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.26%via GHSA
CVE-2026-72796Medium· 5.8
2w ago

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.26%via GHSA
CVE-2026-72794High· 8.6
2w ago

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.25%via OSV
CVE-2026-72795High· 8.6
2w ago

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.24%via GHSA
siyuan-note vulnerabilities (CVEs) · VulnSea