All CVEs — page 52 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows an attacker to inject arbitrary attributes into HTML content, leading to potential remote code execution when the affected control receives focus in the SiYuan application.
This flaw allows an authenticated admin to bypass the normal membership workflow and directly add any user as an admin in their organization, potentially granting unauthorized access.
The flaw allows an attacker with certain API keys or write permissions to inject malicious files into the manifest, potentially leading to OTA manifest poisoning.
The flaw allows authenticated app/org admins to grant channel permissions to non-member users, enabling attackers with admin privileges to bypass organization membership checks and grant unauthorized access.
The flaw allows an apikey_manager to rotate a higher-privileged org_super_admin API key, leading to credential recovery. This matters because it enables privilege escalation and unauthorized access.