Technology · SiYuan
SiYuan vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 154 vulnerabilities in SiYuan: 0 in the last 7 days and 130 in the last 90 days, 32 of them critical and 0 exploited in the wild. The most recent, CVE-2026-93591, was published on 18 September 2026.
- Last 7 days
- 0
- Last 90 days
- 130
- Critical, all time
- 32
- Exploited in the wild
- 0
Latest SiYuan vulnerabilities
- CVE-2026-93591: SiYuan SQL injection in graph query via unescaped taghighCVSS 7.6EPSS 0.3%
- CVE-2026-92986: SiYuan unescaped HTML rendering in backlink dock treehighCVSS 8.8EPSS 0.8%
- CVE-2026-92985: SiYuan cross-site scripting in bookmark renderinghighCVSS 8.8EPSS 0.8%
- CVE-2026-87815: SiYuan path traversal in removeRiffDeck endpointhighCVSS 8.7EPSS 0.5%
- CVE-2026-87814: SiYuan stored XSS in search asset previewhighCVSS 7.3EPSS 0.4%
- CVE-2026-87813: SiYuan stored XSS in Search Assets via unescaped filenameshighCVSS 7.3EPSS 0.4%
- CVE-2026-87812: SiYuan stored cross-site scripting in Bazaar package cardsmediumCVSS 6.8EPSS 0.4%
- CVE-2026-87811: SiYuan stored XSS in notebook template pathshighCVSS 7.3EPSS 0.4%
- CVE-2026-87810: Siyuan information disclosure in fullTextSearchBlock search endpointmediumCVSS 5.3EPSS 0.3%
- CVE-2026-87809: Siyuan information disclosure in export preview and copyStdMarkdownmediumCVSS 6.5EPSS 0.4%
- CVE-2026-87808: SiYuan read-only boundary bypass in fullTextSearchBlock SQL modemediumCVSS 4.9EPSS 0.4%
- CVE-2026-87807: SiYuan authenticated SQL injection in fullTextSearchBlockhighCVSS 7.5EPSS 0.4%
- CVE-2026-72789: SiYuan publish-access gate treats encrypted notebooks as public by defaulthighCVSS 8.6EPSS 0.5%
- CVE-2026-72790: SiYuan getNotebookInfo unauthorized disclosure in APImediumCVSS 5.8EPSS 0.3%
- SiYuan getAttributeViewFieldViews missing authorizationmediumCVSS 5.8
- CVE-2026-86712: SiYuan paste handler code execution via clipboard MIME typehighCVSS 8.8EPSS 0.7%
- CVE-2026-86192: SiYuan authorization bypass in attribute-view endpointmediumCVSS 6.5EPSS 0.4%
- CVE-2026-86191: SiYuan information disclosure in getAttributeViewKeysByID endpointmediumCVSS 4.3EPSS 0.3%
- CVE-2026-72792: SiYuan tag API information disclosure via password bypassmediumCVSS 5.8EPSS 0.3%
- CVE-2026-72793: SiYuan getConf information disclosure of session key and secretshighCVSS 8.6EPSS 0.4%
- CVE-2026-72795: SiYuan embedded block content leak via missing publish-access filteringhighCVSS 8.6EPSS 0.4%
- CVE-2026-72794: SiYuan session-cookie signing key disclosure in /api/system/getConfhighCVSS 8.6EPSS 0.4%
- CVE-2026-72796: SiYuan static routes access control bypassmediumCVSS 5.8EPSS 0.4%
- CVE-2026-72797: SiYuan getEncryptedNotebookStatus information disclosuremediumCVSS 5.8EPSS 0.3%
- CVE-2026-72798: SiYuan renderAttributeView missing authorization in related-database contenthighCVSS 8.6EPSS 0.4%
Most severe SiYuan vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-69084: SiYuan arbitrary SQL execution via searchEmbedBlockcriticalCVSS 10EPSS 1.6%
- CVE-2026-69083: SiYuan fullTextSearchAssetContent SQL injection and REGEXP breakoutcriticalCVSS 10EPSS 0.5%
- CVE-2026-72811: SiYuan backlink search SQL injection via unescaped metadata concatenationcriticalCVSS 10EPSS 0.4%
- SiYuan SQL injection in backlink/mention searchcriticalCVSS 10
- SiYuan SQL injection in fullTextSearchAssetContent endpointcriticalCVSS 10
- SiYuan searchEmbedBlock SQL injectioncriticalCVSS 10
- CVE-2026-66012: SiYuan missing authorization in MCP kernel endpointcriticalCVSS 10
- CVE-2026-50551: SiYuan stored XSS to RCE in Attribute View asset cell renderercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-54067: SiYuan stored XSS to RCE via CSS snippet breakoutcriticalCVSS 9.9EPSS 0.3%
- CVE-2026-54158: SiYuan Stored XSS to RCE in attribute-view cell renderercriticalCVSS 9.9EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 6 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 4 | 3 | |
| 27 Jul 2026 | 3 | 1 | |
| 3 Aug 2026 | 8 | 2 | |
| 10 Aug 2026 | 37 | 7 | |
| 17 Aug 2026 | 5 | 1 | |
| 24 Aug 2026 | 8 | 0 | |
| 31 Aug 2026 | 43 | 4 | |
| 7 Sep 2026 | 13 | 0 | |
| 14 Sep 2026 | 3 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/siyuan.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "SiYuan vulnerabilities", https://junglewise.ai/threats/technologies/siyuan, 26 September 2026.