CVE-2026-87807: Siyuan-Note Siyuan
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter. Attackers can inject UNION SELECT statements to read the entire blocks table, bypassing publish-access controls and exposing all document content and sensitive attributes.
Affected products
- Siyuan-Note Siyuan: before 3.8.2 (fixed in 3.8.2)
Published 2026-09-09. Last modified 2026-10-08.