B3log

Siyuan

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.43%
  • Veröffentlicht 03.01.2025 17:15:09
  • Zuletzt bearbeitet 14.05.2025 14:39:30

SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can cra...

  • EPSS 0.38%
  • Veröffentlicht 12.12.2024 02:15:32
  • Zuletzt bearbeitet 05.06.2025 20:41:33

SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists in Siyuan's `/api/template/render` endpoint. The absence of proper validation on the path parameter allows attackers to access sens...

  • EPSS 0.31%
  • Veröffentlicht 12.12.2024 02:15:32
  • Zuletzt bearbeitet 05.06.2025 20:41:46

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download a...

  • EPSS 0.16%
  • Veröffentlicht 12.12.2024 02:15:32
  • Zuletzt bearbeitet 05.06.2025 20:41:57

SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is vulnerable to both arbitrary file write to the host and stored cross-site scripting (via the file write). Version 3.1.16 contains...

  • EPSS 0.56%
  • Veröffentlicht 12.12.2024 02:15:32
  • Zuletzt bearbeitet 05.06.2025 20:42:58

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 29.11.2024 20:15:21
  • Zuletzt bearbeitet 14.04.2025 14:57:23

A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 29.11.2024 20:15:20
  • Zuletzt bearbeitet 14.04.2025 14:30:52

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.

Exploit
  • EPSS 0.17%
  • Veröffentlicht 29.11.2024 20:15:20
  • Zuletzt bearbeitet 14.04.2025 14:57:53

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.

Exploit
  • EPSS 0.43%
  • Veröffentlicht 29.11.2024 20:15:20
  • Zuletzt bearbeitet 14.04.2025 14:57:37

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.

Exploit
  • EPSS 0.7%
  • Veröffentlicht 21.07.2024 05:15:03
  • Zuletzt bearbeitet 13.05.2025 15:37:35

A vulnerability has been found in SiYuan 3.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file PDF.js of the component PDF Handler. The manipulation leads to cross site scripting. The attack can b...