CVE-2024-2692: b3log Siyuan
Critical severity, CVSS 9.0. EPSS: 0.7% chance of exploitation in the next 30 days.
SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.
Affected products
- b3log Siyuan: version 3.0.3 only
Published 2024-04-04. Last modified 2026-06-17.