Back exploit-intel.com CVE-2026-73052: SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names [CRITICAL] CVSS 9.4 Exploit Intelligence — Recent CVEs / 15h SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort . Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort , with Node integration enabled in the desktop client enabling code execution.
Default status: unaffected
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
