CVE-2026-104451

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page revisions through GET requests lacking CSRF token validation. Attackers can lure write-capable users into a top-level navigation with the restoreRevisionId parameter, silently overwriting current page content with stale or vandalized revisions.

  • Published Oct 2, 2026
  • CVSS 5.3 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-104451 at the National Vulnerability Database