Yeswiki

Yeswiki

68 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 02.10.2026 11:38:18
  • Zuletzt bearbeitet 02.10.2026 21:16:54

YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attacke...

  • EPSS 0.36%
  • Veröffentlicht 02.10.2026 11:38:17
  • Zuletzt bearbeitet 02.10.2026 14:17:08

YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete en...

  • EPSS 0.32%
  • Veröffentlicht 02.10.2026 11:38:17
  • Zuletzt bearbeitet 02.10.2026 16:16:46

YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication action through the render handler's content parameter. Attacker...

  • EPSS 0.29%
  • Veröffentlicht 02.10.2026 11:38:16
  • Zuletzt bearbeitet 06.10.2026 17:17:12

YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary hosts and ports via the {{valeur}} action's url parameter. Attackers can submit the action thro...

  • EPSS 0.29%
  • Veröffentlicht 02.10.2026 11:38:15
  • Zuletzt bearbeitet 02.10.2026 15:17:06

YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side requests via the idtypeannonce parameter of /api/entries/bazarlist. Because isValidURL() always return...

  • EPSS 0.34%
  • Veröffentlicht 02.10.2026 11:38:15
  • Zuletzt bearbeitet 02.10.2026 14:17:08

YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recov...

  • EPSS 0.3%
  • Veröffentlicht 02.10.2026 11:38:14
  • Zuletzt bearbeitet 02.10.2026 16:16:46

YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. Unauthenticated or unprivileged attackers can embed these ac...

  • EPSS -
  • Veröffentlicht 04.09.2026 23:51:46
  • Zuletzt bearbeitet 08.09.2026 21:05:26

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.

  • EPSS -
  • Veröffentlicht 04.09.2026 23:51:35
  • Zuletzt bearbeitet 08.09.2026 21:05:26

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary SQL ...

  • EPSS -
  • Veröffentlicht 04.09.2026 23:51:19
  • Zuletzt bearbeitet 08.09.2026 21:05:26

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using strip_tags() only. Because strip_tags() does not escape double quotes, an attacker can break out ...