CVSS
9.0
CVSS v3.1
EPSS
N/A
Exploit Prediction Score
Published
August 15, 2026
Exploitability
No EPSS data available
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).