Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-87814

Опубликовано: 09 сент. 2026
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted text assets in a workspace can execute JavaScript in the SiYuan origin when victims preview the assets, enabling authenticated API requests and workspace manipulation.

EPSS

Процентиль: 11%
0.00207
Низкий

7.3 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.3
github
15 дней назад

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted text assets in a workspace can execute JavaScript in the SiYuan origin when victims preview the assets, enabling authenticated API requests and workspace manipulation.

EPSS

Процентиль: 11%
0.00207
Низкий

7.3 High

CVSS3

Дефекты

CWE-79