yeswiki

49 known vulnerabilities in yeswiki, 3 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-105224 CVSS 5.1 medium YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by…
  • CVE-2026-104473 CVSS 5.1 medium YesWiki before 4.5.3 contains multiple reflected cross-site scripting vulnerabilities that allow remote attackers to inject JavaScript…
  • CVE-2026-104472 CVSS 8.7 high YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated…
  • CVE-2026-104471 CVSS 8.6 high YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the…
  • CVE-2026-104470 CVSS 5.3 medium YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows page editors to make the server fetch arbitrary URLs…
  • CVE-2026-104469 CVSS 7.6 high YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does…
  • CVE-2026-104468 CVSS 6.3 medium YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links…
  • CVE-2026-104467 CVSS 9.2 critical YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to…
  • CVE-2026-104466 CVSS 5.1 medium YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or…
  • CVE-2026-104465 CVSS 5.1 medium YesWiki before 4.6.7 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via…
  • CVE-2026-104464 CVSS 8.8 high YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET…
  • CVE-2026-104463 CVSS 8.3 high YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests…
  • CVE-2026-104462 CVSS 8.8 high YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute…
  • CVE-2026-104461 CVSS 5.1 medium YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file…
  • CVE-2026-104460 CVSS 8.7 high YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are…
  • CVE-2026-104459 CVSS 6.9 medium YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService that allows unauthenticated attackers to…
  • CVE-2026-104458 CVSS 8.3 high YesWiki before 4.6.7 contains a server-side request forgery vulnerability in validateKeyIdUrl() that allows unauthenticated attackers to…
  • CVE-2026-104457 CVSS 8.8 high YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute…
  • CVE-2026-104456 CVSS 7.2 high YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is…
  • CVE-2026-104455 CVSS 6.9 medium YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content…
  • CVE-2026-104454 CVSS 6.9 medium YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an O(n^2) markdown-link regex…
  • CVE-2026-104453 CVSS 5.3 medium YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action that allows attackers to delete tag…
  • CVE-2026-104452 CVSS 5.3 medium YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the filemanager page handler, which deletes page attachments…
  • CVE-2026-104451 CVSS 5.3 medium YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page…
  • CVE-2026-104450 CVSS 8.2 high YesWiki before 4.6.7 contains a missing authorization flaw in the pointimage action (tools/attach/actions/pointimage.php), which saves…
  • CVE-2026-104449 CVSS 8.3 high YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page…
  • CVE-2026-104448 CVSS 7.2 high YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page…
  • CVE-2026-104447 CVSS 7.1 high YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete…
  • CVE-2026-104446 CVSS 6.9 medium YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send…
  • CVE-2026-104445 CVSS 8.8 high YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP…