Siyuan
This hub aggregates every CVE we track for Siyuan, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
87
CVEs tracked
37
Critical
28
High
0
In CISA KEV
Severity distribution
CRITICAL37HIGH28MEDIUM21LOW1
Monthly trend
0
0
4
4
1
0
0
0
0
0
0
0
0
0
0
2
5
3
27
7
4
9
11
8
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Siyuan.
- CVE-2026-69086SiYuan before v3.7.3 Path Traversal via unvalidated avID7.7
- CVE-2026-69085SiYuan before v3.7.3 SQL Injection via searchDocs10.0
- CVE-2026-69084SiYuan before v3.7.3 SQL Injection via searchEmbedBlock10.0
- CVE-2026-69083SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent10.0
- CVE-2026-68587SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction8.6
- CVE-2026-68585SiYuan before v3.7.3 Metadata Disclosure via getBlockInfo5.8
- CVE-2026-68586SiYuan before v3.7.3 Content Disclosure via getBacklinkDoc8.6
- CVE-2026-68584SiYuan before v3.7.3 Authentication Bypass via Content Endpoints8.6
- CVE-2026-66396SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL8.4
- CVE-2026-66395SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol9.6
- CVE-2026-66394SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass8.7
- CVE-2026-66012SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP10.0
- CVE-2026-65607SiYuan before v3.7.2 Path Traversal via /export/temp/6.5
- CVE-2026-65606SiYuan before v3.7.2 Cross-Site Scripting to RCE9.6
- CVE-2026-65605SiYuan before v3.7.2 Stored XSS to RCE via Attribute View9.6
Product normalization is registry-driven with AI assist and human review. How it works