Vulnerabilities
Report: Update: CVE-2026-40322 - SiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE
2026-04-17
0 views
admin
CVE ID :CVE-2026-40322 Published : April 16, 2026, 11:16 p.m. | 1 hour, 52 minutes ago Description :SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to
CVE Details
CVE ID
Published
April 16, 2026
🏷️ Tags
reportupdate40322siyuanmermaidjavascriptinjectionleadsstoredelectron
More from Vulnerabilities
Report: CVE-2026-4817 - MasterStudy LMS <= 3.7.25 - authenticated (subscriber+) time-based blind sql inje
2026-04-17
0
Report: CVE-2026-5162 - Royal Addons for Elementor <= 1.7.1056 - authenticated (contributor+) stored cros
2026-04-17
0
Report: CVE-2026-5231 - WP Statistics <= 14.16.4 - unauthenticated stored cross-site scripting via 'utm_s
2026-04-17
0
Report: CVE-2026-40922 - SiYuan: Incomplete sanitization of bazaar README allows stored XSS via iframe sr
2026-04-17
0
Trending
1
CVE-2025-61481: Critical Remote Code Execution Vulnerability in MikroTik RouterOS & SwitchOS
2025-10-27 • 189 views
2
CVE-2025-43939: Dell Unity OS Command Injection (High)
2025-10-30 • 148 views
3
Google disputes false claims of massive Gmail data breach
2025-10-30 • 130 views
4
Microsoft: DNS outage impacts Azure and Microsoft 365 services
2025-10-30 • 88 views
5
3.5B Accounts, 1 Critical Flaw: Meta Closes WhatsApp Data-Harvesting
2025-11-25 • 81 views