CVE Tools

Github.com/siyuan-note/siyuan/kernel

36 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Github.com/siyuan-note/siyuan/kernel, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Github.com/siyuan-note/siyuan/kernel CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Github.com/siyuan-note/siyuan/kernel CVEs per month
MonthCVEs
2024-100
2024-110
2024-124
2025-011
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-122
2026-014
2026-022
2026-0315
2026-044
2026-050
2026-060
2026-070
2026-080
2026-094

Severity

How the 36 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical627%
  • High836%
  • Medium836%

Latest CVEs

The 15 most recently published vulnerabilities affecting Github.com/siyuan-note/siyuan/kernel.

  1. GHSA-57v5-wqx3-cgj4SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews—
  2. GHSA-7j72-f6wg-cxw6SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)—
  3. GHSA-gw25-m53r-qh88SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)—
  4. GHSA-99rq-75j6-5j9fSiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass—
  5. GHSA-hjh7-r5w8-5872SiYuan: Path Traversal via Double URL Encoding in `/export/` Endpoint (Incomplete Fix Bypass for CVE-2026-30869)—
  6. GHSA-8q5w-mmxf-48jgSiYuan has incomplete fix for CVE-2026-33066: XSS—
  7. GHSA-vw86-c94w-v3x4SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`—
  8. GHSA-7m5h-w69j-qgggSiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView`—
  9. CVE-2026-32767SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API9.8
  10. CVE-2026-32751SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface9.0
  11. CVE-2026-32749SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write7.6
  12. CVE-2026-32747SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrets6.8
  13. GHSA-fq2j-j8hc-8vw8SiYuan Vulnerable to Arbitrary File Read in Desktop Publish Service—
  14. GHSA-v3mg-9v85-fcm7SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS—
  15. GHSA-xp2m-98x8-rpj6SiYuan Vulnerable to Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store