b3log records
70 published records for vendor b3log.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 65.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')29
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')16
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-285 Improper Authorization2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-284 Improper Access Control1
The weakness classes this vendor ships most often: where to look.
CWEAll records
70 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-10469No exploit | b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URIb3log · symphony · CWE-434 | Critical9.8 | — | 2.1% | Apr 27, 2018 |
39Monitor | CVE-2024-23049No exploit | An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.b3log · symphony · CWE-77 | Critical9.8 | — | 1.2% | Feb 5, 2024 |
39Monitor | CVE-2026-30869No exploit | SiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakageb3log · siyuan · CWE-22 | Critical9.8 | — | 1.1% | Mar 10, 2026 |
39Monitor | CVE-2026-32767No exploit | SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search APIb3log · siyuan · CWE-89 | Critical9.8 | — | 0.7% | Mar 19, 2026 |
39Monitor | CVE-2024-53507No exploit | A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.b3log · siyuan · CWE-89 | Critical9.8 | — | 0.6% | Nov 29, 2024 |
39Monitor | CVE-2024-53504No exploit | A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.b3log · siyuan · CWE-89 | Critical9.8 | — | 0.6% | Nov 29, 2024 |
39Monitor | CVE-2024-53506No exploit | A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.b3log · siyuan · CWE-89 | Critical9.8 | — | 0.5% | Nov 29, 2024 |
39Monitor | CVE-2024-53505No exploit | A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.b3log · siyuan · CWE-89 | Critical9.8 | — | 0.5% | Nov 29, 2024 |
38Monitor | CVE-2026-34449No exploit | SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injectionb3log · siyuan · CWE-942 | Critical9.6 | — | 0.8% | Mar 31, 2026 |
36Monitor | CVE-2024-2692No exploit | SiYuan 3.0.3 - RCE via Server Side XSSb3log · siyuan · CWE-79 | Critical9.0 | — | 0.7% | Apr 3, 2024 |
36Monitor | CVE-2026-34448No exploit | SiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop clientb3log · siyuan · CWE-79 | Critical9.0 | — | 0.7% | Mar 31, 2026 |
36Monitor | CVE-2026-39846No exploit | SiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in synced table captionsb3log · siyuan · CWE-79 | Critical9.0 | — | 0.7% | Apr 7, 2026 |
36Monitor | CVE-2026-32749No exploit | SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file writeb3log · siyuan · CWE-22 | Critical9.1 | — | 0.6% | Mar 19, 2026 |
36Monitor | CVE-2026-40322No exploit | SiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCEb3log · siyuan · CWE-79 | Critical9.0 | — | 0.5% | Apr 16, 2026 |
35Monitor | CVE-2025-67488No exploit | SiYuan: ZipSlip -> Arbitrary File Overwrite -> RCEb3log · siyuan · CWE-22 | High8.8 | — | 0.4% | Dec 9, 2025 |
34Monitor | CVE-2024-55657No exploit | SiYuan has an arbitrary file read via /api/template/renderb3log · siyuan · CWE-22 | High8.7 | — | 0.7% | Dec 11, 2024 |
34Monitor | CVE-2024-55658No exploit | SiYuan has an arbitrary file read and path traversal via /api/export/exportResourcesb3log · siyuan · CWE-22 | High8.7 | — | 0.6% | Dec 11, 2024 |
34Monitor | CVE-2026-34605Proof of concept | SiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated )b3log · siyuan · CWE-79 | High8.6 | — | 0.6% | Mar 31, 2026 |
34Monitor | CVE-2025-21609No exploit | SiYuan has an arbitrary file deletion vulnerabilityb3log · siyuan · CWE-459 | High8.7 | — | 0.6% | Jan 3, 2025 |
34Monitor | CVE-2026-40107No exploit | SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Renderingb3log · siyuan · CWE-918 | High8.7 | — | 0.5% | Apr 9, 2026 |
34Monitor | CVE-2026-40318No exploit | SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`b3log · siyuan · CWE-24 | High8.5 | — | 0.4% | Apr 16, 2026 |
34Monitor | CVE-2024-55659No exploit | SiYuan has an arbitrary file write in the host via /api/asset/uploadb3log · siyuan · CWE-22 | High8.7 | — | 0.4% | Dec 11, 2024 |
33Monitor | CVE-2026-23851No exploit | SiYuan Vulnerable to Arbitrary File Read via File Copy Functionalityb3log · siyuan · CWE-22 | High8.3 | — | 0.5% | Jan 19, 2026 |
33Monitor | CVE-2026-32110No exploit | SiYuan has a Full-Read SSRF via /api/network/forwardProxyb3log · siyuan · CWE-918 | High8.3 | — | 0.4% | Mar 11, 2026 |
32Monitor | CVE-2026-40259No exploit | SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via removeUnusedAttributeView APIb3log · siyuan · CWE-285 | High8.1 | — | 0.5% | Apr 16, 2026 |
- CVE-2018-1046940Plan
b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI
CriticalCVSS 9.8No exploitEPSS 2%b3log · symphonyApr 27, 2018
- CVE-2024-2304939Monitor
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.
CriticalCVSS 9.8No exploitEPSS 1%b3log · symphonyFeb 5, 2024
- CVE-2026-3086939Monitor
SiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage
CriticalCVSS 9.8No exploitEPSS 1%b3log · siyuanMar 10, 2026
- CVE-2026-3276739Monitor
SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API
CriticalCVSS 9.8No exploitEPSS 1%b3log · siyuanMar 19, 2026
- CVE-2024-5350739Monitor
A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.
CriticalCVSS 9.8No exploitEPSS 1%b3log · siyuanNov 29, 2024
- CVE-2024-5350439Monitor
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.
CriticalCVSS 9.8No exploitEPSS 1%b3log · siyuanNov 29, 2024
- CVE-2024-5350639Monitor
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.
CriticalCVSS 9.8No exploitEPSS 1%b3log · siyuanNov 29, 2024
- CVE-2024-5350539Monitor
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.
CriticalCVSS 9.8No exploitEPSS 1%b3log · siyuanNov 29, 2024
- CVE-2026-3444938Monitor
SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection
CriticalCVSS 9.6No exploitEPSS 1%b3log · siyuanMar 31, 2026
- CVE-2024-269236Monitor
SiYuan 3.0.3 - RCE via Server Side XSS
CriticalCVSS 9.0No exploitEPSS 1%b3log · siyuanApr 3, 2024
- CVE-2026-3444836Monitor
SiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop client
CriticalCVSS 9.0No exploitEPSS 1%b3log · siyuanMar 31, 2026
- CVE-2026-3984636Monitor
SiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in synced table captions
CriticalCVSS 9.0No exploitEPSS 1%b3log · siyuanApr 7, 2026
- CVE-2026-3274936Monitor
SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write
CriticalCVSS 9.1No exploitEPSS 1%b3log · siyuanMar 19, 2026
- CVE-2026-4032236Monitor
SiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE
CriticalCVSS 9.0No exploitEPSS 1%b3log · siyuanApr 16, 2026
- CVE-2025-6748835Monitor
SiYuan: ZipSlip -> Arbitrary File Overwrite -> RCE
HighCVSS 8.8No exploitEPSS 0%b3log · siyuanDec 9, 2025
- CVE-2024-5565734Monitor
SiYuan has an arbitrary file read via /api/template/render
HighCVSS 8.7No exploitEPSS 1%b3log · siyuanDec 11, 2024
- CVE-2024-5565834Monitor
SiYuan has an arbitrary file read and path traversal via /api/export/exportResources
HighCVSS 8.7No exploitEPSS 1%b3log · siyuanDec 11, 2024
- CVE-2026-3460534Monitor
SiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated )
HighCVSS 8.6Proof of conceptEPSS 1%b3log · siyuanMar 31, 2026
- CVE-2025-2160934Monitor
SiYuan has an arbitrary file deletion vulnerability
HighCVSS 8.7No exploitEPSS 1%b3log · siyuanJan 3, 2025
- CVE-2026-4010734Monitor
SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering
HighCVSS 8.7No exploitEPSS 0%b3log · siyuanApr 9, 2026
- CVE-2026-4031834Monitor
SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`
HighCVSS 8.5No exploitEPSS 0%b3log · siyuanApr 16, 2026
- CVE-2024-5565934Monitor
SiYuan has an arbitrary file write in the host via /api/asset/upload
HighCVSS 8.7No exploitEPSS 0%b3log · siyuanDec 11, 2024
- CVE-2026-2385133Monitor
SiYuan Vulnerable to Arbitrary File Read via File Copy Functionality
HighCVSS 8.3No exploitEPSS 1%b3log · siyuanJan 19, 2026
- CVE-2026-3211033Monitor
SiYuan has a Full-Read SSRF via /api/network/forwardProxy
HighCVSS 8.3No exploitEPSS 0%b3log · siyuanMar 11, 2026
- CVE-2026-4025932Monitor
SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via removeUnusedAttributeView API
HighCVSS 8.1No exploitEPSS 1%b3log · siyuanApr 16, 2026