Skip to content
CVE-2026-73052: SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names [CRITICAL] CVSS 9.4 Exploit Intelligence — Recent CVEs / 15h SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.

CVE-2026-73052: SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names [CRITICAL] CVSS 9.4 Exploit Intelligence — Recent CVEs / 15h SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.

exploit-intel.com • August 16, 2026

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort . Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort , with Node integration enabled in the desktop client enabling code execution.

Default status: unaffected

Extracted Entities

Vulnerabilities (2)