Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string substitution instead of parameterized queries. Attackers can distribute malicious SiYuan documents or packages with crafted template columns that execute arbitrary SQL on a victim's kernel when the package is imported and rendered, enabling read and write access across notebooks. | |
| Title | SiYuan before v3.7.4 SQL Injection via queryBlocks template | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-12T20:54:52.026Z
Reserved: 2026-08-10T15:11:49.794Z
Link: CVE-2026-72807
No data.
Status : Received
Published: 2026-08-12T20:17:52.837
Modified: 2026-08-12T20:17:52.837
Link: CVE-2026-72807
No data.
OpenCVE Enrichment
No data.