← All credits
manus-pi
7 vulnerability records and advisories credit this contributor.
CVE-2026-104410
SiYuan before 3.8.5 Information Disclosure via /api/export/preview
CVE-2026-103763
SiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfo
CVE-2026-103762
SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints
CVE-2026-103261
Tornado before 6.5.9 Denial of Service via Query String
CVE-2026-101091
SiYuan before v3.8.4 SQL Injection via Block Query Embed
CVE-2026-91039
dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover
CVE-2026-86818
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization