VendorsB3logsiyuanall versions
Vulnerabilities

B3log (Yunnan Liandi Technology Co., Ltd) SiYuan

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

55CVEs
CVE-2026-25992
SiYuan has a File Read Interface Case Bypass Vulnerability
Published 2026-02-10 · Analyzed
7.5EPSS 0.007
CVE-2026-33203
SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass
Published 2026-03-20 · Analyzed
7.5EPSS 0.006
CVE-2026-32815
SiYuan: Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure
Published 2026-03-19 · Analyzed
7.5EPSS 0.005
CVE-2026-30926
SiYuan Note publish service authorization bypass allows low-privilege users to modify notebook content
Published 2026-03-09 · Analyzed
7.1EPSS 0.003
CVE-2026-32747
SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrets
Published 2026-03-19 · Analyzed
6.8EPSS 0.005
CVE-2026-33194
SiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /home
Published 2026-03-20 · Analyzed
6.8EPSS 0.005
CVE-2026-32750
SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes
Published 2026-03-19 · Analyzed
6.8EPSS 0.005
CVE-2026-32704
SiYuan renderSprig: missing admin check allows any user to read full workspace DB
Published 2026-03-13 · Analyzed
6.5EPSS 0.004
CVE-2026-31809
SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS
Published 2026-03-10 · Analyzed
6.4EPSS 0.006
CVE-2026-31807
SiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS
Published 2026-03-10 · Analyzed
6.4EPSS 0.005
CVE-2026-23847
SiYuan Vulnerable to Reflected Cross-Site Scripting (XSS) via /api/icon/getDynamicIcon
Published 2026-01-19 · Analyzed
6.1EPSS 0.003
CVE-2026-23645
SiYuan Vulnerable to Stored Cross-Site Scripting (XSS) via Unrestricted SVG File Upload
Published 2026-01-16 · Analyzed
6.1EPSS 0.003
CVE-2026-40922
SiYuan: Incomplete sanitization of bazaar README allows stored XSS via iframe srcdoc (incomplete fix for CVE-2026-33066)
Published 2026-04-16 · Modified
5.4EPSS 0.004
CVE-2024-6938
SiYuan PDF PDF.js cross site scripting
Published 2024-07-21 · Analyzed
5.4EPSS 0.004
CVE-2026-25647
Lute has a Stored Cross-Site Scripting (XSS) via Markdown hyperlink
Published 2026-02-06 · Analyzed
5.4EPSS 0.003
← Prev2 / 2