siyuan-note has 92 CVEs on record. Disclosure cadence is accelerating: 87 in the last 90 days against 3 in the 90 before. The busiest recent month was September 2026 with 69. The median CVSS is 7.6 (high), with 14 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (24) and CWE-862 (24). Most affected products: github.com/siyuan-note/siyuan/kernel (53), siyuan (39).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.6
- Publish → KEV
- —
- Last 90 days
- 87 prev 3
Weakness classes
Products
- github.com/siyuan-note/siyuan/kernel 53
- siyuan 39
92
Total CVEs
14
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-69084Critical· 10.0SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write67CVE-2026-69083Critical· 10.0SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB67CVE-2026-66012Critical· 10.0SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement67CVE-2026-66395Critical· 9.6SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link65CVE-2026-65606Critical· 9.6SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler65
siyuan-note vulnerabilities
CVEs affecting siyuan-note, newest first. Open any entry for full detail, references, and exploit status.
92 CVEsRSS
CVE-2026-33066MediumSiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.68%via OSV
CVE-2026-56397MediumSiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.70%via GHSA