Skip to content

Known CVE

SiYuan <= 3.6.5 - Unauthenticated Path Traversal

SiYuan <= 3.6.5 contains a path traversal via double URL-encoding in the /assets/ route (publish mode port 6808), allowing unauthenticated attackers to read arbitrary files inside WorkspaceDir including conf/conf.json which exposes the API token and access auth code.

CVE-2026-54066

High2026CVSS 7.5CWE-22

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website