Where
-Infinity
0

Vendor Risk Score

See how siyuan compares to other vendors in security performance

View Risk Score →

SiYuan SiYuanSiYuan before v3.7.4 Authentication Bypass via WebSocket

Risk 43
Severity
7.5
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji

Risk 74
Severity
9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Stored XSS via Attribute-View Field Names

Risk 74
Severity
9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Stored XSS via select option color

Risk 74
Severity
9
First published (updated )

SiYuan SiYuansiyuan before v3.7.4 Server-Side Template Injection via attribute-view

Risk 36
Severity
6.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SiYuan SiYuanSiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth

Risk 86
Severity
9.8
First published (updated )

SiYuan SiYuanSiYuan before 3.7.4 Brute-Force via authFilePublishAccess

Risk 43
Severity
7.5
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Remote Code Execution via Template Calculation

Risk 74
Severity
9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Remote Code Execution via Menu Metadata

Risk 74
Severity
9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Information Disclosure via authFilePublishAccess

Risk 33
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SiYuan SiYuanSiYuan before v3.7.4 Missing Authorization via refreshBacklink

Risk 41
Severity
6.9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget

Risk 49
Severity
9.2
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Information Disclosure via getBookmarkLabels

Risk 33
Severity
6.9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Information Disclosure via getOutlineStorage

Risk 33
Severity
6.9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Path Traversal via getUniqueFilename

Risk 33
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SiYuan SiYuanSiYuan before v3.7.4 Authentication Bypass via Localhost Trust

Risk 65
Severity
7.1
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Information Disclosure via getFileAnnotation

Risk 33
Severity
6.9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Information Disclosure via Block Endpoints

Risk 33
Severity
6.9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Information Disclosure via Encryption Key Material

Risk 47
Severity
8.7
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Information Disclosure via Unfiltered API

Risk 33
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SiYuan SiYuanSiYuan before v3.7.4 Information Disclosure via Path Resolution

Risk 33
Severity
6.9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Information Disclosure via getEncryptedNotebookStatus

Risk 33
Severity
6.9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Information Disclosure via /api/system/getConf

Risk 49
Severity
9.2
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Information Disclosure via getAttributeViewFieldViews

Risk 33
Severity
6.9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.4 Information Disclosure via getNotebookInfo

Risk 33
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SiYuan SiYuanSiYuan before v3.7.3 SQL Injection via searchEmbedBlock

Risk 73
Severity
9.9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.3 Metadata Disclosure via getBlockInfo

Risk 33
Severity
6.9
First published (updated )

SiYuan SiYuanSiYuan before v3.7.3 Authentication Bypass via Content Endpoints

Risk 49
Severity
9.2
First published (updated )

SiYuan SiYuan DesktopSiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol

Risk 80
Severity
9.4
First published (updated )

SiYuan SiYuanSiYuan before v3.7.2 Stored XSS to RCE via title-img IAL

Risk 71
Severity
9.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203