CVE-2026-25992
- EPSS 0.06%
- Veröffentlicht 10.02.2026 18:16:38
- Zuletzt bearbeitet 23.02.2026 17:58:09
SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive string equality checks to block access to sensitive files. On case-insensitive file systems such as Windows, attackers can bypass res...
CVE-2026-25647
- EPSS 0.03%
- Veröffentlicht 06.02.2026 19:16:09
- Zuletzt bearbeitet 24.02.2026 20:59:10
Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has a Stored Cross-Site Scripting (XSS) vulnerability in the Markdown rendering engine. An attacker can inject malicious JavaScript i...
CVE-2026-25539
- EPSS 0.51%
- Veröffentlicht 04.02.2026 21:39:12
- Zuletzt bearbeitet 11.02.2026 19:10:21
SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allowing authenticated users to write files to arbitrary locations on the filesystem. This can lead to Rem...
CVE-2026-23852
- EPSS 0.17%
- Veröffentlicht 19.01.2026 20:15:49
- Zuletzt bearbeitet 30.01.2026 15:08:46
SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attacker to inject arbitrary HTML attributes into the `icon` attribute of a block via the `/api/attr/setBl...
CVE-2026-23851
- EPSS 0.04%
- Veröffentlicht 19.01.2026 19:57:29
- Zuletzt bearbeitet 30.01.2026 15:12:24
SiYuan is a personal knowledge management system. Versions prior to 3.5.4 contain a logic vulnerability in the /api/file/globalCopyFiles endpoint. The function allows authenticated users to copy files from any location on the server's filesystem into...
CVE-2026-23850
- EPSS 0.09%
- Veröffentlicht 19.01.2026 19:52:58
- Zuletzt bearbeitet 30.01.2026 15:35:36
SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted server side html-rendering which allows arbitrary file read (LFD). Version 3.5.4 fixes the issue.
CVE-2026-23847
- EPSS 0.04%
- Veröffentlicht 19.01.2026 19:46:08
- Zuletzt bearbeitet 30.01.2026 15:36:42
SiYuan is a personal knowledge management system. Versions prior to 3.5.4 are vulnerable to reflected cross-site scripting in /api/icon/getDynamicIcon due to unsanitized SVG input. The endpoint generates SVG images for text icons (type=8). The conten...
CVE-2026-23645
- EPSS 0.01%
- Veröffentlicht 16.01.2026 19:20:06
- Zuletzt bearbeitet 30.01.2026 19:32:11
SiYuan is self-hosted, open source personal knowledge management software. Prior to 3.5.4-dev2, a Stored Cross-Site Scripting (XSS) vulnerability exists in SiYuan Note. The application does not sanitize uploaded SVG files. If a user uploads and views...
CVE-2025-68948
- EPSS 0.05%
- Veröffentlicht 27.12.2025 00:21:31
- Zuletzt bearbeitet 02.01.2026 19:30:38
SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption i...
CVE-2025-67488
- EPSS 0.06%
- Veröffentlicht 09.12.2025 20:32:37
- Zuletzt bearbeitet 30.01.2026 19:30:11
SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce and below contain function importZipMd which is vulnerable to ZipSlips, allowing an authenticated user to overwrite files on the sys...