CVE-2026-23847 | SiYuan up to 3.5.3 /api/icon/getDynamicIcon cross site scripting (ID 16844 / EUVD-2026-3293)
A vulnerability identified as problematic has been detected in SiYuan up to 3.5.3. The affected element is an unknown function of the file /api/icon/getDynamicIcon. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2026-23847. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.