Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Smavl

#17271of 57,338
17.1Total CVSS
Vulnerabilities · 2
High
2
PT-2026-99314
8.5
2026-09-26
Siyuan · Siyuan · CVE-2026-100643
**Name of the Vulnerable Software and Affected Versions** SiYuan versions prior to 3.8.4 **Description** Authenticated attackers can inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates because four stored Attribute View values in textarea elements are not properly escaped. This allows the execution of stored JavaScript when other users open affected database menus. In the Electron desktop app, if `nodeIntegration` is enabled, this can lead to command execution with SiYuan process privileges. **Recommendations** Update SiYuan to version 3.8.4 or later.
PT-2026-99316
8.6
2026-09-26
Siyuan · Siyuan · CVE-2026-100645
**Name of the Vulnerable Software and Affected Versions** SiYuan versions 3.7.0 through 3.8.3 **Description** A stored cross-site scripting issue exists in the gallery and kanban database renderers because field descriptions are not escaped in `aria-label` attributes. In the Electron desktop application when `nodeIntegration` is enabled, this allows the injection of JavaScript that can call Node.js `child process` APIs to execute arbitrary commands with user privileges. **Recommendations** Update SiYuan to version 3.8.4 or later.