Filtered by vendor B3log
Subscriptions
Filtered by product Siyuan
Subscriptions
Total
7 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-21609 | 1 B3log | 1 Siyuan | 2025-05-14 | 9.1 Critical |
SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a payload to exploit this vulnerability, resulting in the deletion of arbitrary files on the server. Commit d9887aeec1b27073bec66299a9a4181dc42969f3 fixes this vulnerability and is expected to be available in version 3.1.19. | ||||
CVE-2024-6938 | 1 B3log | 1 Siyuan | 2025-05-13 | 3.5 Low |
A vulnerability has been found in SiYuan 3.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file PDF.js of the component PDF Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271993 was assigned to this vulnerability. | ||||
CVE-2024-2692 | 1 B3log | 1 Siyuan | 2025-05-13 | 9.6 Critical |
SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS. | ||||
CVE-2024-53505 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2025-04-14 | 9.8 Critical |
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent. | ||||
CVE-2024-53506 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2025-04-14 | 9.8 Critical |
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs. | ||||
CVE-2024-53507 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2025-04-14 | 9.8 Critical |
A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems. | ||||
CVE-2024-53504 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2025-04-14 | 9.8 Critical |
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory. |
Page 1 of 1.