Vulnerability index

Browse CVEs

67 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Siyuan HIGH 7.1
CVE-2026-30926

SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note …

Fix: 3.5.10+
Fix from $1,950 2026-03-10
Siyuan MEDIUM 6.1
CVE-2026-29183

SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon A…

Fix: 3.5.9+
Fix from $1,600 2026-03-06
Siyuan HIGH 8.8
CVE-2026-29073

SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic a…

Fix: after 3.5.9
Fix from $1,950 2026-03-06
Siyuan HIGH 7.5
CVE-2026-25992

SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive string equality checks to block …

Fix: 3.5.5+
Fix from $1,950 2026-02-10
Siyuan MEDIUM 5.4
CVE-2026-25647

Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has a Stored Cross-Site Scriptin…

Patch available
Fix from $1,600 2026-02-06
Siyuan HIGH 7.2
CVE-2026-25539

SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allow…

Fix: after 3.5.3
Fix from $1,950 2026-02-04
Siyuan CRITICAL 9.6
CVE-2026-23852

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attac…

Fix: 3.5.4+
Fix from $2,300 2026-01-19
Siyuan HIGH 7.5
CVE-2026-23850

SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted server side html-rendering whi…

Fix: 3.5.4+
Fix from $1,950 2026-01-19
Siyuan MEDIUM 6.5
CVE-2026-23851

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 contain a logic vulnerability in the /api/file/globalCopyFiles endpoint. Th…

Fix: 3.5.4+
Fix from $1,600 2026-01-19
Siyuan MEDIUM 6.1
CVE-2026-23847

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 are vulnerable to reflected cross-site scripting in /api/icon/getDynamicIco…

Fix: 3.5.4+
Fix from $1,600 2026-01-19
Siyuan MEDIUM 6.1
CVE-2026-23645

SiYuan is self-hosted, open source personal knowledge management software. Prior to 3.5.4-dev2, a Stored Cross-Site Scripting (XSS) vulnerability exi…

Fix: 3.5.4+
Fix from $1,600 2026-01-16
Siyuan HIGH 8.1
CVE-2025-68948

SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardco…

Fix: 3.5.2+
Fix from $1,950 2025-12-27
Siyuan HIGH 8.8
CVE-2025-67488

SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce and below contain function impo…

Fix: 3.5.0+
Fix from $1,950 2025-12-09
Siyuan CRITICAL 9.1
CVE-2025-21609

SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. T…

Patch available
Fix from $2,300 2025-01-03
Siyuan CRITICAL 9.8
CVE-2024-55660

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side…

Patch available
Fix from $2,300 2024-12-12
Siyuan HIGH 7.5
CVE-2024-55657

SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists in Siyuan's `/api/template/ren…

Patch available
Fix from $1,950 2024-12-12
Siyuan HIGH 7.5
CVE-2024-55658

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary fi…

Patch available
Fix from $1,950 2024-12-12
Siyuan MEDIUM 5.4
CVE-2024-55659

SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is vulnerable to both arbitrary…

Patch available
Fix from $1,600 2024-12-12
Siyuan CRITICAL 9.8
CVE-2024-53507

A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.

No fix yet
Fix from $2,300 2024-11-29
Siyuan CRITICAL 9.8
CVE-2024-53504

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.

No fix yet
Fix from $2,300 2024-11-29
Siyuan CRITICAL 9.8
CVE-2024-53505

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.

No fix yet
Fix from $2,300 2024-11-29
Siyuan CRITICAL 9.8
CVE-2024-53506

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.

No fix yet
Fix from $2,300 2024-11-29
Siyuan MEDIUM 5.4
CVE-2024-6938

A vulnerability has been found in SiYuan 3.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file …

No fix yet
Fix from $1,600 2024-07-21
Vditor MEDIUM 5.9
CVE-2024-39150

vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet.

Fix: after 3.9.8
Fix from $1,600 2024-07-05
Vditor MEDIUM 6.1
CVE-2024-34449

Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.

No fix yet
Fix from $1,600 2024-05-03
Siyuan CRITICAL 9.0
CVE-2024-2692

SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.

No fix yet
Fix from $2,300 2024-04-04
Symphony CRITICAL 9.8
CVE-2024-23049

An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.

Fix: after 3.6.3
Fix from $2,300 2024-02-05
Vditor MEDIUM 6.1
CVE-2021-32855

Vditor is a browser-side Markdown editor. Versions prior to 3.8.7 are vulnerable to copy-paste cross-site scripting (XSS). For this particular type o…

Fix: 3.8.7+
Fix from $1,600 2023-02-21
Vditor MEDIUM 5.4
CVE-2022-0350

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.

Fix: 3.8.13+
Fix from $1,600 2022-03-31
Vditor MEDIUM 5.4
CVE-2022-0341

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12.

Fix: 3.8.12+
Fix from $1,600 2022-03-14