Vendor
SiYuan vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 159 vulnerabilities in SiYuan: 9 in the last 7 days and 135 in the last 90 days, 32 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100646, was published on 26 September 2026. 1 technology has a page of its own.
- Last 7 days
- 9
- Last 90 days
- 135
- Critical, all time
- 32
- Exploited in the wild
- 0
About SiYuan
Open source note-taking application with local-first architecture and support for markdown and outlining.
SiYuan technologies
- SiYuan154
Latest SiYuan vulnerabilities
- CVE-2026-100646: SiYuan authentication bypass via missing Origin headerhighCVSS 8.1
- CVE-2026-100645: SiYuan stored cross-site scripting in gallery and kanban renderershighCVSS 8
- CVE-2026-100643: SiYuan stored XSS in Attribute View textarea elementshighCVSS 8
- CVE-2026-100642: SiYuan cross-site request forgery in CheckAuth lock-screen bypasshighCVSS 7.6
- CVE-2026-100641: SiYuan stored XSS in flashcard content before v3.8.4highCVSS 8
- CVE-2026-100636: SiYuan path traversal in exportBrowserHTMLhighCVSS 7.6
- CVE-2026-100635: SiYuan authentication bypass in publish servicemediumCVSS 5.9
- CVE-2026-100634: SiYuan IPC handler lacks sender validation in siyuan-send-windowsmediumCVSS 4.7
- CVE-2026-100633: SiYuan sensitive-path guard bypass in recursive MCP file operationsmediumCVSS 6.5
- CVE-2026-93923: SiYuan stored cross-site scripting in outline and bookmark renderinghighCVSS 8.8EPSS 0.6%
- CVE-2026-93591: SiYuan SQL injection in graph query via unescaped taghighCVSS 7.6EPSS 0.3%
- CVE-2026-92986: SiYuan unescaped HTML rendering in backlink dock treehighCVSS 8.8EPSS 0.8%
- CVE-2026-92985: SiYuan cross-site scripting in bookmark renderinghighCVSS 8.8EPSS 0.8%
- CVE-2026-87815: SiYuan path traversal in removeRiffDeck endpointhighCVSS 8.7EPSS 0.5%
- CVE-2026-87814: SiYuan stored XSS in search asset previewhighCVSS 7.3EPSS 0.4%
- CVE-2026-87813: SiYuan stored XSS in Search Assets via unescaped filenameshighCVSS 7.3EPSS 0.4%
- CVE-2026-87812: SiYuan stored cross-site scripting in Bazaar package cardsmediumCVSS 6.8EPSS 0.4%
- CVE-2026-87811: SiYuan stored XSS in notebook template pathshighCVSS 7.3EPSS 0.4%
- CVE-2026-87810: Siyuan information disclosure in fullTextSearchBlock search endpointmediumCVSS 5.3EPSS 0.3%
- CVE-2026-87809: Siyuan information disclosure in export preview and copyStdMarkdownmediumCVSS 6.5EPSS 0.4%
- CVE-2026-87808: SiYuan read-only boundary bypass in fullTextSearchBlock SQL modemediumCVSS 4.9EPSS 0.4%
- CVE-2026-87807: SiYuan authenticated SQL injection in fullTextSearchBlockhighCVSS 7.5EPSS 0.4%
- CVE-2026-72789: SiYuan publish-access gate treats encrypted notebooks as public by defaulthighCVSS 8.6EPSS 0.5%
- CVE-2026-72790: SiYuan getNotebookInfo unauthorized disclosure in APImediumCVSS 5.8EPSS 0.3%
- SiYuan getAttributeViewFieldViews missing authorizationmediumCVSS 5.8
Most severe SiYuan vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-69084: SiYuan arbitrary SQL execution via searchEmbedBlockcriticalCVSS 10EPSS 1.6%
- CVE-2026-69083: SiYuan fullTextSearchAssetContent SQL injection and REGEXP breakoutcriticalCVSS 10EPSS 0.5%
- CVE-2026-72811: SiYuan backlink search SQL injection via unescaped metadata concatenationcriticalCVSS 10EPSS 0.4%
- SiYuan SQL injection in backlink/mention searchcriticalCVSS 10
- SiYuan searchEmbedBlock SQL injectioncriticalCVSS 10
- SiYuan SQL injection in fullTextSearchAssetContent endpointcriticalCVSS 10
- CVE-2026-66012: SiYuan missing authorization in MCP kernel endpointcriticalCVSS 10
- CVE-2026-50551: SiYuan stored XSS to RCE in Attribute View asset cell renderercriticalCVSS 9.9EPSS 0.8%
- CVE-2026-54067: SiYuan stored XSS to RCE via CSS snippet breakoutcriticalCVSS 9.9EPSS 0.5%
- CVE-2026-54158: SiYuan Stored XSS to RCE in attribute-view cell renderercriticalCVSS 9.9EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 6 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 4 | 3 | |
| 27 Jul 2026 | 3 | 1 | |
| 3 Aug 2026 | 8 | 2 | |
| 10 Aug 2026 | 35 | 7 | |
| 17 Aug 2026 | 5 | 1 | |
| 24 Aug 2026 | 8 | 0 | |
| 31 Aug 2026 | 40 | 4 | |
| 7 Sep 2026 | 13 | 0 | |
| 14 Sep 2026 | 4 | 0 | |
| 21 Sep 2026 | 9 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/siyuan.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "SiYuan vulnerabilities", https://junglewise.ai/threats/vendors/siyuan, 26 September 2026.