VendorsB3logsiyuanany version
Vulnerabilities

B3log (Yunnan Liandi Technology Co., Ltd) SiYuan any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2026-32938
SiYuan has an Arbitrary File Read in its Desktop Publish Service
Published 2026-03-20 · Analyzed
9.9EPSS 0.006
CVE-2026-30869
SiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage
Published 2026-03-09 · Analyzed
9.8EPSS 0.011
CVE-2026-32767
SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API
Published 2026-03-20 · Analyzed
9.8EPSS 0.007
CVE-2026-33670
SiYuan has directory traversal within its publishing service
Published 2026-03-26 · Analyzed
9.8EPSS 0.006
CVE-2026-33669
SiYuan has Arbitrary Document Reading within the Publishing Service
Published 2026-03-26 · Analyzed
9.8EPSS 0.005
CVE-2026-34449
SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection
Published 2026-03-31 · Analyzed
9.6EPSS 0.008
CVE-2026-23852
SiYuan vulnerable to Stored XSS / RCE via `setBlockAttrs` icon attribute
Published 2026-01-19 · Analyzed
9.6EPSS 0.008
CVE-2026-29183
SiYuan: Unauthenticated reflected SVG XSS in `/api/icon/getDynamicIcon` (`type=8`) enables arbitrary JavaScript execution
Published 2026-03-06 · Analyzed
9.3EPSS 0.007
CVE-2026-32940
SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183)
Published 2026-03-20 · Analyzed
9.3EPSS 0.005
CVE-2026-25539
SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE
Published 2026-02-04 · Analyzed
9.1EPSS 0.010
CVE-2026-32749
SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write
Published 2026-03-19 · Analyzed
9.1EPSS 0.006
CVE-2026-32751
SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface
Published 2026-03-19 · Analyzed
9.0EPSS 0.008
CVE-2026-34448
SiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop client
Published 2026-03-31 · Analyzed
9.0EPSS 0.007
CVE-2026-33066
SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
Published 2026-03-20 · Analyzed
9.0EPSS 0.007
CVE-2026-39846
SiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in synced table captions
Published 2026-04-07 · Analyzed
9.0EPSS 0.007
CVE-2026-33067
SiYuan has Stored XSS to RCE via Unsanitized Bazaar Package Metadata
Published 2026-03-20 · Analyzed
9.0EPSS 0.007
CVE-2026-40322
SiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE
Published 2026-04-16 · Analyzed
9.0EPSS 0.005
CVE-2026-29073
SiYuan: Direct SQL Query API accessible to Reader-level users enables unauthorized database access
Published 2026-03-06 · Analyzed
8.8EPSS 0.005
CVE-2025-67488
SiYuan: ZipSlip -> Arbitrary File Overwrite -> RCE
Published 2025-12-09 · Analyzed
8.8EPSS 0.004
CVE-2026-40107
SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering
Published 2026-04-09 · Analyzed
8.7EPSS 0.005
CVE-2026-34605
SiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated )
Published 2026-03-31 · Analyzed
8.6EPSS 0.006
CVE-2026-34585
SiYuan: Stored XSS in imported .sy.zip content leads to arbitrary command execution
Published 2026-03-31 · Analyzed
8.6EPSS 0.004
CVE-2026-40318
SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`
Published 2026-04-16 · Analyzed
8.5EPSS 0.004
CVE-2026-23851
SiYuan Vulnerable to Arbitrary File Read via File Copy Functionality
Published 2026-01-19 · Analyzed
8.3EPSS 0.005
CVE-2026-32110
SiYuan has a Full-Read SSRF via /api/network/forwardProxy
Published 2026-03-11 · Analyzed
8.3EPSS 0.004
CVE-2026-40259
SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via removeUnusedAttributeView API
Published 2026-04-16 · Analyzed
8.1EPSS 0.005
CVE-2025-68948
SiYuan: Information Disclosure and Authentication Bypass via Hardcoded Session Secret
Published 2025-12-27 · Analyzed
8.1EPSS 0.002
CVE-2026-23850
SiYuan vulnerable to arbitrary file read
Published 2026-01-19 · Analyzed
7.8EPSS 0.006
CVE-2026-33476
SiYuan has an Unauthenticated Arbitrary File Read via Path Traversal
Published 2026-03-20 · Modified
7.5EPSS 0.031
CVE-2026-34453
SiYuan: Broken access control in /api/bookmark/getBookmark allows unauthenticated publish visitors to read password-protected bookmarked content
Published 2026-03-31 · Analyzed
7.5EPSS 0.015
CVE-2026-25992
SiYuan has a File Read Interface Case Bypass Vulnerability
Published 2026-02-10 · Analyzed
7.5EPSS 0.007
CVE-2026-33203
SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass
Published 2026-03-20 · Analyzed
7.5EPSS 0.006
CVE-2026-32815
SiYuan: Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure
Published 2026-03-19 · Analyzed
7.5EPSS 0.005
CVE-2026-30926
SiYuan Note publish service authorization bypass allows low-privilege users to modify notebook content
Published 2026-03-09 · Analyzed
7.1EPSS 0.003
CVE-2026-32747
SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrets
Published 2026-03-19 · Analyzed
6.8EPSS 0.005
CVE-2026-33194
SiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /home
Published 2026-03-20 · Analyzed
6.8EPSS 0.005
CVE-2026-32750
SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes
Published 2026-03-19 · Analyzed
6.8EPSS 0.005
CVE-2026-32704
SiYuan renderSprig: missing admin check allows any user to read full workspace DB
Published 2026-03-13 · Analyzed
6.5EPSS 0.004
CVE-2026-31809
SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS
Published 2026-03-10 · Analyzed
6.4EPSS 0.006
CVE-2026-31807
SiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS
Published 2026-03-10 · Analyzed
6.4EPSS 0.005
1 / 2Next →