Vulnerability index

Browse CVEs

67 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-30926 SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note … Siyuan 3.5.10+ Fix from $1,9502026-03-10 MEDIUM 6.1 CVE-2026-29183 SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon A… Siyuan 3.5.9+ Fix from $1,6002026-03-06 HIGH 8.8 CVE-2026-29073 SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic a… Siyuan after 3.5.9 Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-25992 SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive string equality checks to block … Siyuan 3.5.5+ Fix from $1,9502026-02-10 MEDIUM 5.4 CVE-2026-25647 Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has a Stored Cross-Site Scriptin… Siyuan Patch available Fix from $1,6002026-02-06 HIGH 7.2 CVE-2026-25539 SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allow… Siyuan after 3.5.3 Fix from $1,9502026-02-04 CRITICAL 9.6 CVE-2026-23852 SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attac… Siyuan 3.5.4+ Fix from $2,3002026-01-19 HIGH 7.5 CVE-2026-23850 SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted server side html-rendering whi… Siyuan 3.5.4+ Fix from $1,9502026-01-19 MEDIUM 6.5 CVE-2026-23851 SiYuan is a personal knowledge management system. Versions prior to 3.5.4 contain a logic vulnerability in the /api/file/globalCopyFiles endpoint. Th… Siyuan 3.5.4+ Fix from $1,6002026-01-19 MEDIUM 6.1 CVE-2026-23847 SiYuan is a personal knowledge management system. Versions prior to 3.5.4 are vulnerable to reflected cross-site scripting in /api/icon/getDynamicIco… Siyuan 3.5.4+ Fix from $1,6002026-01-19 MEDIUM 6.1 CVE-2026-23645 SiYuan is self-hosted, open source personal knowledge management software. Prior to 3.5.4-dev2, a Stored Cross-Site Scripting (XSS) vulnerability exi… Siyuan 3.5.4+ Fix from $1,6002026-01-16 HIGH 8.1 CVE-2025-68948 SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardco… Siyuan 3.5.2+ Fix from $1,9502025-12-27 HIGH 8.8 CVE-2025-67488 SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce and below contain function impo… Siyuan 3.5.0+ Fix from $1,9502025-12-09 CRITICAL 9.1 CVE-2025-21609 SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. T… Siyuan Patch available Fix from $2,3002025-01-03 CRITICAL 9.8 CVE-2024-55660 SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side… Siyuan Patch available Fix from $2,3002024-12-12 HIGH 7.5 CVE-2024-55657 SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists in Siyuan's `/api/template/ren… Siyuan Patch available Fix from $1,9502024-12-12 HIGH 7.5 CVE-2024-55658 SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary fi… Siyuan Patch available Fix from $1,9502024-12-12 MEDIUM 5.4 CVE-2024-55659 SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is vulnerable to both arbitrary… Siyuan Patch available Fix from $1,6002024-12-12 CRITICAL 9.8 CVE-2024-53507 A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems. Siyuan No fix yet Fix from $2,3002024-11-29 CRITICAL 9.8 CVE-2024-53504 A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory. Siyuan No fix yet Fix from $2,3002024-11-29 CRITICAL 9.8 CVE-2024-53505 A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent. Siyuan No fix yet Fix from $2,3002024-11-29 CRITICAL 9.8 CVE-2024-53506 A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs. Siyuan No fix yet Fix from $2,3002024-11-29 MEDIUM 5.4 CVE-2024-6938 A vulnerability has been found in SiYuan 3.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file … Siyuan No fix yet Fix from $1,6002024-07-21 MEDIUM 5.9 CVE-2024-39150 vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet. Vditor after 3.9.8 Fix from $1,6002024-07-05 MEDIUM 6.1 CVE-2024-34449 Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true. Vditor No fix yet Fix from $1,6002024-05-03 CRITICAL 9.0 CVE-2024-2692 SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS. Siyuan No fix yet Fix from $2,3002024-04-04 CRITICAL 9.8 CVE-2024-23049 An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component. Symphony after 3.6.3 Fix from $2,3002024-02-05 MEDIUM 6.1 CVE-2021-32855 Vditor is a browser-side Markdown editor. Versions prior to 3.8.7 are vulnerable to copy-paste cross-site scripting (XSS). For this particular type o… Vditor 3.8.7+ Fix from $1,6002023-02-21 MEDIUM 5.4 CVE-2022-0350 Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13. Vditor 3.8.13+ Fix from $1,6002022-03-31 MEDIUM 5.4 CVE-2022-0341 Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12. Vditor 3.8.12+ Fix from $1,6002022-03-14