Where
-Infinity
0

Vendor Risk Score

See how siyuan compares to other vendors in security performance

View Risk Score →

SiYuan SiYuanSiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP

Risk 87
Severity
10
First published (updated )

SiYuan SiYuanSiYuan before v3.7.2 Path Traversal via /export/temp/

Risk 40
Severity
7.1
First published (updated )

SiYuan SiYuan DesktopSiYuan before v3.7.2 Cross-Site Scripting to RCE

Risk 80
Severity
9.4
First published (updated )

SiYuan SiYuanSiYuan: Incomplete IsSensitivePath denylist: globalCopyFiles reads home-dir credential dotfiles into the workspace

Risk 30
Severity
4.9
First published (updated )

SiYuan SiYuanSiYuan: Store XSS To Rce via Asset.render

Risk 82
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SiYuan SiYuanSiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG xlink:href)

Risk 82
Severity
8.6
First published (updated )

SiYuan SiYuanSiYuan: Stored XSS results to Electron RCE in SiYuan marketplace via unescaped `data-obj` attribute (Bypass for CVE-2026-45375's patch)

Risk 74
Severity
9
First published (updated )

SiYuan SiYuanSiYuan: Lute HTML sanitizer allows `<iframe>` tags in Bazaar package README, leading to arbitrary command execution via SiYuan Electron client

Risk 78
Severity
8.7
First published (updated )

SiYuan SiYuanSiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

Risk 82
Severity
9.9
First published (updated )

SiYuan SiYuanSiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

Risk 82
Severity
9.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SiYuan SiYuanSiYuan: Stored XSS in Bazaar marketplace via package README event handlers

Risk 60
Severity
7.1
First published (updated )

SiYuan SiYuanSiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

Risk 80
Severity
9.2
First published (updated )

SiYuan SiYuanSiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon

Risk 35
Severity
5.9
First published (updated )

SiYuan SiYuanSiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

Risk 82
Severity
9.9
First published (updated )

SiYuan SiYuanSiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SiYuan SiYuanSiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README

Risk 80
Severity
9.4
First published (updated )

SiYuan SiYuanSiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README

Risk 80
Severity
9.4
First published (updated )

SiYuan SiYuanSiYuan: Bazaar marketplace renders unescaped package author metadata, allowing XSS and Electron code execution

Risk 71
Severity
8.3
First published (updated )

SiYuan SiYuan DesktopSiYuan Desktop Notification XSS Leads to Electron RCE

Risk 72
Severity
8.8
First published (updated )

SiYuan SiYuanSiYuan: Incomplete Fix Bypass for CVE-2026-30869: Path Traversal via Double URL Encoding in `/export/` Endpoint

Risk 40
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SiYuan SiYuanSiYuan: Incomplete sanitization of bazaar README allows stored XSS via iframe srcdoc (incomplete fix for CVE-2026-33066)

Risk 34
Severity
5.3
First published (updated )

SiYuan SiYuanSiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE

Risk 75
Severity
9.1
First published (updated )

SiYuan SiYuanSiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`

Risk 55
Severity
8.5
First published (updated )

SiYuan SiYuanSiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated )

Risk 73
Severity
8.6
First published (updated )

SiYuan SiYuanSiYuan: Stored XSS in imported .sy.zip content leads to arbitrary command execution

Risk 70
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SiYuan SiYuanSiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection

Risk 80
Severity
9.7
First published (updated )

SiYuan SiYuanSiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop client

Risk 75
Severity
9.1
First published (updated )

SiYuan SiYuanSiYuan: Broken access control in /api/bookmark/getBookmark allows unauthenticated publish visitors to read password-protected bookmarked content

Risk 43
Severity
7.5
First published (updated )

SiYuan SiYuanSiYuan has a Full-Read SSRF via /api/network/forwardProxy

Risk 49
Severity
8.3
EPSS
0.04%
First published (updated )

SiYuan SiYuanSiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS

Risk 41
Severity
6.4
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203