Siyuan
This hub aggregates every CVE we track for Siyuan, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
197
CVEs tracked
50
Critical
71
High
0
In CISA KEV
Severity distribution
HIGH71MEDIUM65CRITICAL50LOW1
Monthly trend
0
4
4
1
0
0
0
0
0
0
0
0
0
0
2
5
3
28
8
7
10
13
81
29
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Siyuan.
- CVE-2026-93923SiYuan through 3.8.4 Stored XSS via Heading Style Attribute8.8
- CVE-2026-93922SiYuan through 3.8.4 Stored XSS via notebook names8.8
- CVE-2026-93921SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint4.3
- CVE-2026-93591SiYuan before 3.8.3 SQL Injection via unescaped tag in graph.go7.6
- CVE-2026-92986SiYuan before 3.8.4 Cross-Site Scripting via Document Title8.8
- CVE-2026-92985SiYuan before 3.8.4 Cross-Site Scripting via Bookmark Labels8.8
- CVE-2026-87815SiYuan before v3.8.2 Path Traversal via removeRiffDeck8.7
- CVE-2026-87814SiYuan before v3.8.2 Stored XSS via Asset Preview7.3
- CVE-2026-87813SiYuan before v3.8.2 Stored XSS via unescaped asset filenames7.3
- CVE-2026-87812SiYuan before v3.8.2 Stored XSS via Bazaar iconURL6.8
- CVE-2026-87811SiYuan before v3.8.2 Stored XSS via notebook template paths7.3
- CVE-2026-87810Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock5.3
- CVE-2026-87809Siyuan before v3.8.2 Information Disclosure via Export Preview6.5
- CVE-2026-87808SiYuan before v3.8.2 Read-Only Boundary Bypass via fullTextSearchBlock4.9
- CVE-2026-87807siyuan before v3.8.2 SQL Injection via fullTextSearchBlock7.5
Product normalization is registry-driven with AI assist and human review. How it works