Yeswiki

Yeswiki

68 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 04.10.2026 15:04:53
  • Zuletzt bearbeitet 05.10.2026 16:17:11

YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by rendering unescaped HTML fetched from a remote URL. Attackers can point tools/bazar/actions/valeur.php at a con...

  • EPSS 0.2%
  • Veröffentlicht 02.10.2026 11:38:37
  • Zuletzt bearbeitet 06.10.2026 17:17:13

YesWiki before 4.5.3 contains multiple reflected cross-site scripting vulnerabilities that allow remote attackers to inject JavaScript through unsanitized parameters such as incomingurl, id, file, tags, and template. Attackers can lure authenticated ...

  • EPSS 0.35%
  • Veröffentlicht 02.10.2026 11:38:36
  • Zuletzt bearbeitet 02.10.2026 15:17:08

YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the download handler with a known page tag and file parameter...

  • EPSS 0.37%
  • Veröffentlicht 02.10.2026 11:38:36
  • Zuletzt bearbeitet 02.10.2026 14:17:09

YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV import preview. Attackers can import a CSV whose file or image field...

  • EPSS 0.22%
  • Veröffentlicht 02.10.2026 11:38:35
  • Zuletzt bearbeitet 04.10.2026 16:16:29

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows page editors to make the server fetch arbitrary URLs via the url parameter of the Bazar valeur action. Attackers can embed the action with a champ parameter in wiki...

  • EPSS 0.23%
  • Veröffentlicht 02.10.2026 11:38:34
  • Zuletzt bearbeitet 06.10.2026 17:17:13

YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session coo...

  • EPSS 0.25%
  • Veröffentlicht 02.10.2026 11:38:34
  • Zuletzt bearbeitet 02.10.2026 15:17:08

YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or b...

  • EPSS 0.37%
  • Veröffentlicht 02.10.2026 11:38:33
  • Zuletzt bearbeitet 02.10.2026 16:16:46

YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like api/c...

  • EPSS 0.17%
  • Veröffentlicht 02.10.2026 11:38:32
  • Zuletzt bearbeitet 02.10.2026 15:17:08

YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or post comments to inject event handlers by placing quotes in markdown image URLs. Attackers can store a crafted m...

  • EPSS 0.17%
  • Veröffentlicht 02.10.2026 11:38:32
  • Zuletzt bearbeitet 06.10.2026 17:17:13

YesWiki before 4.6.7 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the field parameter of the mail handler. Attackers can craft links whose field value breaks out of the ajax-mail-...