B3log

Siyuan

51 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 09.04.2026 21:16:12
  • Zuletzt bearbeitet 16.04.2026 20:28:02

SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In this mode, <img> tags with src attributes survive Mermaid's internal DOMPurify and land in SVG <foreig...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 07.04.2026 21:34:28
  • Zuletzt bearbeitet 16.04.2026 04:32:01

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe esc...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 31.03.2026 21:50:10
  • Zuletzt bearbeitet 03.04.2026 16:01:29

SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the SanitizeSVG function introduced in version 3.6.0 to fix XSS in the unauthenticated /api/icon/getDynamicIcon endpoint can be bypassed by using namespace-...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 31.03.2026 21:47:01
  • Zuletzt bearbeitet 03.04.2026 16:52:22

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is mixed with raw special characters. An attacker can embed a...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 31.03.2026 21:45:17
  • Zuletzt bearbeitet 03.04.2026 16:57:32

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * + Access-Cont...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 31.03.2026 21:44:36
  • Zuletzt bearbeitet 03.04.2026 16:58:40

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with “Cover From -> Asset Field...

Exploit
  • EPSS 3.47%
  • Veröffentlicht 31.03.2026 21:43:32
  • Zuletzt bearbeitet 03.04.2026 16:53:22

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, /api/bookmark/getBookmark filters bookma...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 26.03.2026 21:15:56
  • Zuletzt bearbeitet 30.03.2026 17:02:13

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 26.03.2026 21:14:43
  • Zuletzt bearbeitet 30.03.2026 17:03:33

SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. Version 3.6.2 p...

Exploit
  • EPSS 0.73%
  • Veröffentlicht 20.03.2026 22:34:40
  • Zuletzt bearbeitet 23.03.2026 22:16:31

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to improper path sanitization, attackers can perform directory traversal a...