Back exploit-intel.com CVE-2026-73050: SiYuan before v3.7.4 Stored XSS via select option color [CRITICAL] CVSS 9.4 Exploit Intelligence — Recent CVEs / 20h SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select fiel
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field.
Default status: unaffected
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
