SiYuan vulnerabilities
22 CVEs tracked
The SiYuan note-taking application appears in recent reports with critical vulnerabilities. Versions before v3.7.3 are affected by SQL injection (CVE-2026-69084, CVE-2026-69083, CVE-2026-72811), missing authorization (CVE-2026-66012), stored XSS (CVE-2026-66394), and unauthorized access to published documents (CVE-2026-68585, CVE-2026-68586). Defenders should immediately update to v3.7.4, with focus on user-supplied SQL queries (e.g., searchEmbedBlock endpoint) and publish token management.
Azərbaycanca: SiYuan qeydiyyat tətbiqi son hesabatlarda kritik boşluqlarla müşahidə olunur. Xüsusilə v3.7.3 öncəsi versiyalar SQL injection (CVE-2026-69084, CVE-2026-69083, CVE-2026-72811), autorizasiya çatışmazlığı (CVE-2026-66012), saxlanılan XSS (CVE-2026-66394) və dərc edilmiş sənədlərə icazəsiz giriş (CVE-2026-68585, CVE-2026-68586) kimi zəifliklərə məruz qalır. Müdafiəçilər dərhal v3.7.4-ə yeniləməli, xüsusilə istifadəçi tərəfindən idarə olunan SQL sorğularını (searchEmbedBlock) və publish token idarəetməsini yoxlamalıdır.
This vendor's CVEs22
- CVE-2026-74906EPSS 0.30%
- CVE-2026-74904EPSS 0.36%
- CVE-2026-74902EPSS 0.15%
- CVE-2026-74868EPSS 0.38%
- CVE-2026-74867EPSS 0.10%
- CVE-2026-74800EPSS 0.29%
- CVE-2026-73608EPSS 0.24%
- CVE-2026-73056EPSS 0.45%
- CVE-2026-73053EPSS 0.28%
- CVE-2026-73048EPSS 0.19%
- CVE-2026-73045EPSS 0.30%
- CVE-2026-73043EPSS 0.37%
- CVE-2026-73041EPSS 0.23%
- CVE-2026-72812EPSS 0.27%
- CVE-2026-72811EPSS 0.25%
- CVE-2026-72810EPSS 0.31%
- CVE-2026-69084EPSS 1%
- CVE-2026-69083EPSS 0.35%
- CVE-2026-68586EPSS 0.24%
- CVE-2026-68585EPSS 0.19%
- CVE-2026-66394EPSS 0.27%
- CVE-2026-66012EPSS 0.55%
This hub is built from skopnix's own reporting on SiYuan: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.