B3log

Siyuan

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 10.02.2026 18:16:38
  • Zuletzt bearbeitet 23.02.2026 17:58:09

SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive string equality checks to block access to sensitive files. On case-insensitive file systems such as Windows, attackers can bypass res...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 06.02.2026 19:16:09
  • Zuletzt bearbeitet 24.02.2026 20:59:10

Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has a Stored Cross-Site Scripting (XSS) vulnerability in the Markdown rendering engine. An attacker can inject malicious JavaScript i...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 04.02.2026 21:39:12
  • Zuletzt bearbeitet 11.02.2026 19:10:21

SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allowing authenticated users to write files to arbitrary locations on the filesystem. This can lead to Rem...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 19.01.2026 20:15:49
  • Zuletzt bearbeitet 30.01.2026 15:08:46

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attacker to inject arbitrary HTML attributes into the `icon` attribute of a block via the `/api/attr/setBl...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 19.01.2026 19:57:29
  • Zuletzt bearbeitet 30.01.2026 15:12:24

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 contain a logic vulnerability in the /api/file/globalCopyFiles endpoint. The function allows authenticated users to copy files from any location on the server's filesystem into...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 19.01.2026 19:52:58
  • Zuletzt bearbeitet 30.01.2026 15:35:36

SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted server side html-rendering which allows arbitrary file read (LFD). Version 3.5.4 fixes the issue.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 19.01.2026 19:46:08
  • Zuletzt bearbeitet 30.01.2026 15:36:42

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 are vulnerable to reflected cross-site scripting in /api/icon/getDynamicIcon due to unsanitized SVG input. The endpoint generates SVG images for text icons (type=8). The conten...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 16.01.2026 19:20:06
  • Zuletzt bearbeitet 30.01.2026 19:32:11

SiYuan is self-hosted, open source personal knowledge management software. Prior to 3.5.4-dev2, a Stored Cross-Site Scripting (XSS) vulnerability exists in SiYuan Note. The application does not sanitize uploaded SVG files. If a user uploads and views...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 27.12.2025 00:21:31
  • Zuletzt bearbeitet 02.01.2026 19:30:38

SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption i...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 09.12.2025 20:32:37
  • Zuletzt bearbeitet 30.01.2026 19:30:11

SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce and below contain function importZipMd which is vulnerable to ZipSlips, allowing an authenticated user to overwrite files on the sys...