Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | < 3.6.1 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32938 | 9.9 CRITICAL | SiYuan has an Arbitrary File Read in its Desktop Publish Service |
| CVE-2026-32767 | 9.8 CRITICAL | SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API |
| CVE-2026-33203 | 7.5 HIGH | SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass |
| CVE-2026-33476 | 7.5 HIGH | SiYuan has an Unauthenticated Arbitrary File Read via Path Traversal |
| CVE-2026-33194 | 6.8 MEDIUM | SiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr |
| CVE-2026-33067 | SiYuan has Stored XSS to RCE via Unsanitized Bazaar Package Metadata | |
| CVE-2026-33066 | SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering |
No comments yet