Vendor
SiYuan Note vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 57 vulnerabilities in SiYuan Note: 5 in the last 7 days and 37 in the last 90 days, 16 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100644, was published on 26 September 2026. 1 technology has a page of its own.
- Last 7 days
- 5
- Last 90 days
- 37
- Critical, all time
- 16
- Exploited in the wild
- 0
SiYuan Note technologies
Latest SiYuan Note vulnerabilities
- CVE-2026-100644: SiYuan SQL injection in graph query endpointhighCVSS 7.5
- CVE-2026-100640: SiYuan authorization omission in siyuan-get IPC handlermediumCVSS 4.7
- CVE-2026-100639: SiYuan gutter attribute injection and remote code executionhighCVSS 8.8
- CVE-2026-100638: SiYuan path traversal in setNotebookIconhighCVSS 7.6
- CVE-2026-100637: SiYuan path traversal in checkoutRepo endpointhighCVSS 7.6
- CVE-2026-93922: SiYuan stored cross-site scripting in Daily Note pickerhighCVSS 8.8EPSS 0.8%
- CVE-2026-93921: SiYuan access control bypass in getDynamicIcon endpointmediumCVSS 4.3EPSS 0.4%
- SiYuan database view metadata disclosure via API endpointinfo
- CVE-2026-72795: SiYuan embedded block content leak via missing publish-access filteringhighCVSS 8.6EPSS 0.4%
- CVE-2026-72794: SiYuan session-cookie signing key disclosure in /api/system/getConfhighCVSS 8.6EPSS 0.4%
- CVE-2026-72796: SiYuan static routes access control bypassmediumCVSS 5.8EPSS 0.4%
- CVE-2026-72798: SiYuan renderAttributeView missing authorization in related-database contenthighCVSS 8.6EPSS 0.4%
- CVE-2026-72803: SiYuan missing publish-access filter on getBlockAttrs and batchGetBlockAttrsmediumCVSS 5.8EPSS 0.3%
- CVE-2026-72804: SiYuan graph endpoints bypass publish password protectionhighCVSS 8.6EPSS 0.4%
- CVE-2026-72809: SiYuan kernel localhost-trust admin bypass on auth-gated endpointshighCVSS 8EPSS 0.3%
- CVE-2026-72810: SiYuan publish-boundary bypass via WebSocket broadcasthighCVSS 8.6EPSS 0.5%
- CVE-2026-68584: SiYuan password-protected document bypass via content API endpointshighCVSS 8.6EPSS 0.5%
- CVE-2026-69083: SiYuan fullTextSearchAssetContent SQL injection and REGEXP breakoutcriticalCVSS 10EPSS 0.5%
- SiYuan path traversal in /export/temp/ branchmediumCVSS 6.5
- CVE-2026-73047: siyuan server-side template injection in attribute-view calculationmediumCVSS 6.2EPSS 0.2%
- CVE-2026-73609: SiYuan getBookmarkLabels information disclosuremediumCVSS 5.8EPSS 0.3%
- Siyuan session cookie signing key disclosure via /api/system/getConfhighCVSS 8.6
- SiYuan path traversal in attribute-view read endpointshighCVSS 7.7
- SiYuan missing authorization in heading transaction endpointshighCVSS 8.6
- SiYuan metadata disclosure in getBlockInfo endpointmediumCVSS 5.8
Most severe SiYuan Note vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-69083: SiYuan fullTextSearchAssetContent SQL injection and REGEXP breakoutcriticalCVSS 10EPSS 0.5%
- CVE-2026-66012: SiYuan missing authorization in MCP kernel endpointcriticalCVSS 10
- CVE-2026-50551: SiYuan stored XSS to RCE in Attribute View asset cell renderercriticalCVSS 9.9EPSS 0.8%
- CVE-2026-54067: SiYuan stored XSS to RCE via CSS snippet breakoutcriticalCVSS 9.9EPSS 0.5%
- CVE-2026-54158: SiYuan Stored XSS to RCE in attribute-view cell renderercriticalCVSS 9.9EPSS 0.5%
- CVE-2026-34449: SiYuan RCE via permissive CORS policy and snippet injectioncriticalCVSS 9.6EPSS 0.8%
- CVE-2026-66395: SiYuan Desktop reflected XSS to RCE in bazaar plugin handlercriticalCVSS 9.6
- CVE-2026-65606: SiYuan XSS to RCE in siyuan:// protocol handlercriticalCVSS 9.6
- CVE-2026-65605: SiYuan stored XSS to RCE in Attribute View database cellscriticalCVSS 9.6
- CVE-2026-34448: SiYuan stored XSS and RCE in Attribute View gallery cover renderingcriticalCVSS 9EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 5 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 4 | 3 | |
| 27 Jul 2026 | 3 | 1 | |
| 3 Aug 2026 | 3 | 0 | |
| 10 Aug 2026 | 3 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 11 | 1 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 2 | 0 | |
| 21 Sep 2026 | 5 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/siyuan-note.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "SiYuan Note vulnerabilities", https://junglewise.ai/threats/vendors/siyuan-note, 27 September 2026.