CVE-2024-53506: b3log Siyuan

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.

Affected products

  • b3log Siyuan: version 3.1.11 only

Published 2024-11-29. Last modified 2026-06-17.