Security Advisory

CVE-2026-73050

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-15 21:44:51
Last updated 2026-08-17 15:44:08
Assigner VulnCheck
CVSS score 9.4
State PUBLISHED

Description

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field.