CVE-2024-53504: b3log Siyuan

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.

Affected products

  • b3log Siyuan: version 3.1.11 only

Published 2024-11-29. Last modified 2026-06-17.