Technology · SiYuan Note
SiYuan Note SiYuan vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 39 vulnerabilities in SiYuan Note SiYuan: 5 in the last 7 days and 21 in the last 90 days, 11 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100644, was published on 26 September 2026.
- Last 7 days
- 5
- Last 90 days
- 21
- Critical, all time
- 11
- Exploited in the wild
- 0
Latest SiYuan Note SiYuan vulnerabilities
- CVE-2026-100644: SiYuan SQL injection in graph query endpointhighCVSS 7.5
- CVE-2026-100640: SiYuan authorization omission in siyuan-get IPC handlermediumCVSS 4.7
- CVE-2026-100639: SiYuan gutter attribute injection and remote code executionhighCVSS 8.8
- CVE-2026-100638: SiYuan path traversal in setNotebookIconhighCVSS 7.6
- CVE-2026-100637: SiYuan path traversal in checkoutRepo endpointhighCVSS 7.6
- CVE-2026-93922: SiYuan stored cross-site scripting in Daily Note pickerhighCVSS 8.8EPSS 0.8%
- CVE-2026-93921: SiYuan access control bypass in getDynamicIcon endpointmediumCVSS 4.3EPSS 0.4%
- SiYuan database view metadata disclosure via API endpointinfo
- CVE-2026-72795: SiYuan embedded block content leak via missing publish-access filteringhighCVSS 8.6EPSS 0.4%
- CVE-2026-72794: SiYuan session-cookie signing key disclosure in /api/system/getConfhighCVSS 8.6EPSS 0.4%
- CVE-2026-72796: SiYuan static routes access control bypassmediumCVSS 5.8EPSS 0.4%
- CVE-2026-72798: SiYuan renderAttributeView missing authorization in related-database contenthighCVSS 8.6EPSS 0.4%
- CVE-2026-72803: SiYuan missing publish-access filter on getBlockAttrs and batchGetBlockAttrsmediumCVSS 5.8EPSS 0.3%
- CVE-2026-72804: SiYuan graph endpoints bypass publish password protectionhighCVSS 8.6EPSS 0.4%
- CVE-2026-72809: SiYuan kernel localhost-trust admin bypass on auth-gated endpointshighCVSS 8EPSS 0.3%
- CVE-2026-72810: SiYuan publish-boundary bypass via WebSocket broadcasthighCVSS 8.6EPSS 0.5%
- CVE-2026-68584: SiYuan password-protected document bypass via content API endpointshighCVSS 8.6EPSS 0.5%
- CVE-2026-69083: SiYuan fullTextSearchAssetContent SQL injection and REGEXP breakoutcriticalCVSS 10EPSS 0.5%
- CVE-2026-66394: SiYuan XSS via SVG sanitizer bypasshighCVSS 8.7EPSS 0.5%
- CVE-2026-65607: SiYuan path traversal in export/temp handlermediumCVSS 6.5EPSS 0.6%
- CVE-2026-59832: SiYuan path traversal in serveSnippets route handlerhighCVSS 7.7EPSS 0.5%
- CVE-2026-54158: SiYuan Stored XSS to RCE in attribute-view cell renderercriticalCVSS 9.9EPSS 0.5%
- CVE-2026-54070: SiYuan stored XSS in Bazaar marketplace package READMEhighCVSS 7.1EPSS 0.3%
- CVE-2026-54069: SiYuan Note unauthenticated admin API access via browser extensionscriticalCVSS 4EPSS 0.6%
- CVE-2026-54068: SiYuan missing authentication and SQL exfiltration in getDynamicIcon APImediumCVSS 5.9EPSS 0.4%
Most severe SiYuan Note SiYuan vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-69083: SiYuan fullTextSearchAssetContent SQL injection and REGEXP breakoutcriticalCVSS 10EPSS 0.5%
- CVE-2026-50551: SiYuan stored XSS to RCE in Attribute View asset cell renderercriticalCVSS 9.9EPSS 0.8%
- CVE-2026-54067: SiYuan stored XSS to RCE via CSS snippet breakoutcriticalCVSS 9.9EPSS 0.5%
- CVE-2026-54158: SiYuan Stored XSS to RCE in attribute-view cell renderercriticalCVSS 9.9EPSS 0.5%
- CVE-2026-34449: SiYuan RCE via permissive CORS policy and snippet injectioncriticalCVSS 9.6EPSS 0.8%
- CVE-2026-34448: SiYuan stored XSS and RCE in Attribute View gallery cover renderingcriticalCVSS 9EPSS 0.7%
- CVE-2026-39846: SiYuan remote code execution via stored XSS in table captionscriticalCVSS 9EPSS 0.7%
- CVE-2026-45375: SiYuan Bazaar XSS and Remote Code Execution via Package MetadatacriticalCVSS 9EPSS 0.4%
- CVE-2026-54069: SiYuan Note unauthenticated admin API access via browser extensionscriticalCVSS 4EPSS 0.6%
- CVE-2026-44670: SiYuan Stored XSS to RCE via Attribute View namescriticalCVSS 4EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 10 | 1 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 2 | 0 | |
| 21 Sep 2026 | 5 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/siyuan-note-siyuan.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "SiYuan Note SiYuan vulnerabilities", https://junglewise.ai/threats/technologies/siyuan-note-siyuan, 27 September 2026.