SiYuan是SiYuan团队开源的一款文档管理软件。 SiYuan 3.7.2及之前版本存在授权问题漏洞,该漏洞源于对getFullHPathByID、getHPathByID、getPathByID、getIDsByHPath和getHPathByPath等文件树路径解析端点未能正确执行发布访问过滤器,可能导致未经身份验证的攻击者枚举完整的私有文档树,包括隐藏、密码保护或禁止发布的文档,造成信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.7.4 |
affected |
3.7.4 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72794 | 8.6 HIGH | siyuan before v3.7.4 Session Cookie Key Disclosure via getConf |
| CVE-2026-72793 | 8.6 HIGH | SiYuan before v3.7.4 Information Disclosure via /api/system/getConf |
| CVE-2026-72804 | 8.6 HIGH | SiYuan before v3.7.4 Authentication Bypass via Graph Endpoints |
| CVE-2026-72789 | 8.6 HIGH | SiYuan before v3.7.4 Authentication Bypass via Encrypted Notebooks |
| CVE-2026-72798 | 8.6 HIGH | SiYuan before v3.7.4 Information Disclosure via renderAttributeView |
| CVE-2026-72795 | 8.6 HIGH | SiYuan before v3.7.4 Information Disclosure via Embed Block |
| CVE-2026-72809 | 8.0 HIGH | SiYuan before v3.7.4 Authentication Bypass via Localhost Trust |
| CVE-2026-72807 | 8.0 HIGH | SiYuan before v3.7.4 SQL Injection via queryBlocks template |
| CVE-2026-72801 | 7.5 HIGH | SiYuan before v3.7.4 Information Disclosure via Encryption Key Material |
| CVE-2026-72790 | 5.8 MEDIUM | SiYuan before v3.7.4 Information Disclosure via getNotebookInfo |
| CVE-2026-72803 | 5.8 MEDIUM | SiYuan before v3.7.4 Information Disclosure via getBlockAttrs |
| CVE-2026-72796 | 5.8 MEDIUM | SiYuan before v3.7.4 Access Control Bypass via Static Routes |
| CVE-2026-72808 | 5.8 MEDIUM | SiYuan before v3.7.4 Information Disclosure via getFileAnnotation |
| CVE-2026-72805 | 5.8 MEDIUM | SiYuan before v3.7.4 Information Disclosure via Block Endpoints |
| CVE-2026-72788 | 5.8 MEDIUM | SiYuan before v3.7.4 Information Disclosure via UILayout Filter |
| CVE-2026-72797 | 5.8 MEDIUM | SiYuan before v3.7.4 Information Disclosure via getEncryptedNotebookStatus |
| CVE-2026-72791 | 5.8 MEDIUM | SiYuan before v3.7.4 Information Disclosure via getAttributeViewFieldViews |
| CVE-2026-72792 | 5.8 MEDIUM | SiYuan before v3.7.4 Information Disclosure via Tag API |
| CVE-2026-72806 | 5.8 MEDIUM | SiYuan before v3.7.4 Authentication Bypass via Attribute View |
| CVE-2026-72800 | 5.8 MEDIUM | SiYuan before v3.7.4 Information Disclosure via Unfiltered API |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet