CVE-2026-87807: Siyuan-Note Siyuan

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter. Attackers can inject UNION SELECT statements to read the entire blocks table, bypassing publish-access controls and exposing all document content and sensitive attributes.

Affected products

Published 2026-09-09. Last modified 2026-10-08.