VulnSea

siyuan-note has 92 CVEs on record. Disclosure cadence is accelerating: 87 in the last 90 days against 3 in the 90 before. The busiest recent month was September 2026 with 69. The median CVSS is 7.6 (high), with 14 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (24) and CWE-862 (24). Most affected products: github.com/siyuan-note/siyuan/kernel (53), siyuan (39).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.6
Publish → KEV
—
Last 90 days
87 prev 3

Products

  • github.com/siyuan-note/siyuan/kernel 53
  • siyuan 39
92
Total CVEs
14
Critical
0
CISA KEV
0
Exploited

siyuan-note vulnerabilities

CVEs affecting siyuan-note, newest first. Open any entry for full detail, references, and exploit status.

92 CVEsRSS

CVE-2026-69084Critical· 10.0PoC
3w ago

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 1.6%via GHSA
CVE-2026-69086High· 7.7
3w ago

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclo…

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.53%via OSV
CVE-2026-69083Critical· 10.0PoC
3w ago

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.47%via GHSA
CVE-2026-65607Medium· 6.5
3w ago

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.59%via OSV
CVE-2026-66394High· 8.7
3w ago

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.47%via OSV
GHSA-99rq-75j6-5j9fHigh· 8.7
3w ago

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
GHSA-gw25-m53r-qh88Medium· 6.5
3w ago

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-59834High· 7.5
3w ago

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.51%via GHSA
CVE-2026-59832High· 7.7
3w ago

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.46%via OSV
GHSA-xx34-6cjg-prh8Critical· 8.6
1mo ago

Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
GHSA-mxjf-vfmv-qfm6Medium· 5.8
1mo ago

Duplicate Advisory: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

Duplicate Advisory: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-72809High· 8.0
1mo ago

SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0…

SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0…

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.30%via NVD
CVE-2026-72805Medium· 5.8
1mo ago

SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata

SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata. Anonymous readers or publish RoleRead…

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via NVD
CVE-2026-72789High· 8.6
1mo ago

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypte…

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.50%via NVD
GHSA-g64v-qqpg-v37hCritical· 8.6
1mo ago

Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-66396High· 8.4PoC
2mo ago

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor pe…

▾ Midnightsiyuan-note · siyuanEPSS 0.54%via NVD
CVE-2026-66395Critical· 9.6PoC
2mo ago

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HT…

▾ Abyssalsiyuan-note · siyuanEPSS 0.56%via NVD
CVE-2026-66012Critical· 10.0PoC
2mo ago

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, i…

▾ Abyssalsiyuan-note · siyuanEPSS 0.76%via NVD
CVE-2026-65606Critical· 9.6PoC
2mo ago

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts t…

▾ Abyssalsiyuan-note · siyuanEPSS 0.79%via NVD
CVE-2026-65605Critical· 9.6PoC
2mo ago

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied wh…

▾ Abyssalsiyuan-note · siyuanEPSS 0.79%via NVD
CVE-2026-50551Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.78%via GHSA
CVE-2026-54066High· 7.5PoC
2mo ago

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 2.4%via GHSA
CVE-2026-54067Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via GHSA
CVE-2026-54068Medium· 5.9
2mo ago

SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon

SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.38%via GHSA
CVE-2026-54069CriticalPoC
2mo ago

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.58%via GHSA
CVE-2026-54070High· 7.1
2mo ago

SiYuan: Stored XSS in Bazaar marketplace via package README event handlers

SiYuan: Stored XSS in Bazaar marketplace via package README event handlers

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.30%via GHSA
CVE-2026-54158Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.51%via GHSA
GHSA-24r3-p3x6-cqvxCritical· 9.6
3mo ago

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-56395Medium
3mo ago

Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.

Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.70%via NVD
CVE-2026-40922Medium· 5.4
5mo ago

SiYuan has incomplete fix for CVE-2026-33066: XSS

SiYuan has incomplete fix for CVE-2026-33066: XSS

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.38%via OSV
siyuan-note vulnerabilities (CVEs) — page 3 · VulnSea