Skip to content

Known CVE

SiYuan - SQL Execution

SiYuan <= v3.7.2 contains a SQL injection caused by passing client-supplied SQL statements verbatim to the main read-write database handle in /api/search/searchEmbedBlock, letting attackers with publish RoleReader token or anonymous access read and modify content, exploit requires publish RoleReader token or disabled publish authentication.

CVE-2026-69084

Critical2026CVSS 10CWE-89

cve2026 · siyuan · sqli · authenticated

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website