CVE Tools

Siyuan-note

172 CVEs tracked since 2024. Since Dec 2024, none of them reached CISA KEV.

Siyuan-note CVEs per month

Dec 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Siyuan-note CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-1240
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03280
2026-0480
2026-05null or fewer
2026-0690
2026-07130
2026-08810
2026-09290

Products

The products that kept showing up in Siyuan-note's monthly top three, with their CVEs summed over those months.

  1. Siyuan1727 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Siyuan-note.

  1. CVE-2026-100646SiYuan before v3.8.4 Authentication Bypass via Missing Origin Header8.1
  2. CVE-2026-100644SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath7.5
  3. CVE-2026-100645SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban8.0
  4. CVE-2026-100643SiYuan before v3.8.4 Stored XSS via Attribute View textarea8.0
  5. CVE-2026-100642SiYuan v2.1.0 before v3.8.4 Cross-Site Request Forgery via CheckAuth7.6
  6. CVE-2026-100641SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content8.0
  7. CVE-2026-100640SiYuan before v3.8.4 Clipboard Data Disclosure via IPC4.7
  8. CVE-2026-100639SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IAL8.8
  9. CVE-2026-100637SiYuan before v3.8.4 Path Traversal via checkoutRepo sessionID7.6
  10. CVE-2026-100638SiYuan before v3.8.4 Path Traversal via setNotebookIcon7.6
  11. CVE-2026-100636SiYuan before v3.8.4 Path Traversal via exportBrowserHTML folder7.6
  12. CVE-2026-100635SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie5.9
  13. CVE-2026-100634SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows4.7
  14. CVE-2026-100633SiYuan 3.8.0 through 3.8.3 Path Traversal via MCP File Operations6.5
  15. CVE-2026-93923SiYuan through 3.8.4 Stored XSS via Heading Style Attribute8.8

The record

Peak rank
#12 in Aug 2026
Busiest month shown
Aug 2026, 81 CVEs
Months with a KEV entry
0 since Dec 2024
Monthly snapshots
7 since 2024
Siyuan-note's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store