CVE-2026-104454
- EPSS 0.4%
- Veröffentlicht 02.10.2026 11:38:25
- Zuletzt bearbeitet 02.10.2026 15:17:07
YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an O(n^2) markdown-link regex. Unauthenticated attackers can submit a small crafted body of bracket characters to the page-edit preview endpoi...
CVE-2026-104453
- EPSS 0.11%
- Veröffentlicht 02.10.2026 11:38:24
- Zuletzt bearbeitet 06.10.2026 17:17:12
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action that allows attackers to delete tag associations by luring administrators to crafted GET links. Attackers can supply a wide id range in the delete_tag par...
CVE-2026-104452
- EPSS 0.11%
- Veröffentlicht 02.10.2026 11:38:23
- Zuletzt bearbeitet 02.10.2026 15:17:07
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the filemanager page handler, which deletes page attachments on GET requests without validating a CSRF token. Attackers can lure a logged-in page owner or administrator into ...
CVE-2026-104451
- EPSS 0.13%
- Veröffentlicht 02.10.2026 11:38:23
- Zuletzt bearbeitet 02.10.2026 14:17:08
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page revisions through GET requests lacking CSRF token validation. Attackers can lure write-capable users into a top-lev...
CVE-2026-104450
- EPSS 0.27%
- Veröffentlicht 02.10.2026 11:38:22
- Zuletzt bearbeitet 02.10.2026 15:17:07
YesWiki before 4.6.7 contains a missing authorization flaw in the pointimage action (tools/attach/actions/pointimage.php), which saves content to an attacker-chosen page with write ACL checks bypassed. Unauthenticated attackers can POST pagetag, titl...
CVE-2026-104449
- EPSS 0.28%
- Veröffentlicht 02.10.2026 11:38:21
- Zuletzt bearbeitet 06.10.2026 17:17:12
YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via the Bazar entry-creation flow. Attackers can submit a crafted...
CVE-2026-104448
- EPSS 0.16%
- Veröffentlicht 02.10.2026 11:38:21
- Zuletzt bearbeitet 02.10.2026 15:17:07
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback parameter without checking a CSRF token. Attackers can lure a logged...
CVE-2026-104447
- EPSS 0.13%
- Veröffentlicht 02.10.2026 11:38:20
- Zuletzt bearbeitet 02.10.2026 14:17:08
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed packages via unprotected GET requests. Attackers can lure a logged-in administrator to a crafted link wi...
CVE-2026-104446
- EPSS 0.44%
- Veröffentlicht 02.10.2026 11:38:19
- Zuletzt bearbeitet 02.10.2026 15:17:07
YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. Attackers can POST an XMLHttpRequest to the mail handler without field or type...
CVE-2026-104445
- EPSS 0.4%
- Veröffentlicht 02.10.2026 11:38:19
- Zuletzt bearbeitet 06.10.2026 17:17:12
YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete o...