Siyuan

Vendor:

First CVE: Apr 4, 2024 · Active for 2 years

55
Total CVEs
More Total CVEs than 98% of tracked products
18.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Siyuan over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 4, 2024
2 years ago
Most Recent CVE
Apr 17, 2026
102 days ago

CVE Severity & Scoring

Siyuan55 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local1 (1.8%)
Network54 (98.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low54 (98.2%)
High1 (1.8%)
Unknown0 (0.0%)
User Interaction
None33 (60.0%)
Unknown0 (0.0%)
Required22 (40.0%)
Privileges Required
Low21 (38.2%)
High5 (9.1%)
None29 (52.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitor
Mar 31, 20267.541NOYES
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to i
Mar 20, 20267.537NOYES
SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting th
Mar 31, 20269.636NONO
SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon API endpoint "GET /api/icon/getD
Mar 6, 20266.135NOYES
SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. T
Apr 7, 20269.034NONO
SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a v
Mar 31, 20269.034NONO
SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the SanitizeSVG function introduced in version 3.6.0 to fix XSS in the unauthenticated
Mar 31, 20266.133NOYES
SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) checks href attributes for the javascript: prefix using strings.HasPrefix().
Mar 10, 20266.133NOYES
SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) blocks dangerous elements (<script>, <iframe>, <foreignobject>) and removes
Mar 10, 20266.133NOYES
SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attacker to inject arbitrary HTML at
Jan 19, 20269.633NONO

Exploit Exposure

Signals from CVEs in this product scope (55 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
10.9% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (55 CVEs).

Media Mentions

Signals from CVEs in this product scope (55 CVEs).

Top CNAs Publishing CVEs For Siyuan

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.5.425.80.2%00
3.1.1819.10.6%00
3.1.1547.50.6%00
3.1.1149.80.5%00
3.1.015.40.4%00
3.0.319.00.7%00