Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

yeswiki — Vulnerabilities & Security Advisories 64

All 64 CVE vulnerabilities found in yeswiki, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the product yeswiki, covering specific weakness types and security advisories. It collects disclosed security issues affecting this software, detailing various bug classes and the time range during which these flaws were identified and patched. Readers can use this resource to track the vendor’s advisory history, understand recurring weakness categories impacting the product, and review the complete vulnerability timeline for yeswiki. The data supports security teams in assessing risk exposure and planning remediation efforts based on historical patterns and current threats.

Vendor: YesWiki

CVE ID Title CVSS Severity Published
CVE-2026-104472 YesWiki before 4.6.7 Missing Authorization via Attachment Download Handler CWE-862 7.5 High 2026-10-02
CVE-2026-104473 YesWiki before 4.5.3 Multiple Reflected XSS via BazaR and listpages CWE-79 6.1 Medium 2026-10-02
CVE-2026-104471 YesWiki before 4.6.7 Unrestricted File Upload via Bazar CSV Import CWE-434 7.2 High 2026-10-02
CVE-2026-104469 YesWiki before 4.6.7 Session Fixation via Login in AuthController.php CWE-384 6.8 Medium 2026-10-02
CVE-2026-104470 YesWiki before 4.6.7 SSRF and XSS via Bazar valeur Action CWE-79 7.4 High 2026-10-02
CVE-2026-104468 YesWiki before 4.6.7 Non-Expiring Password Reset Tokens via LostPasswordAction CWE-613 4.8 Medium 2026-10-02
CVE-2026-104466 YesWiki before 4.6.7 Stored XSS via Wakka Markdown Image src Attribute CWE-79 5.4 Medium 2026-10-02
CVE-2026-104467 YesWiki before 4.6.7 Authorization Bypass via Public API Mode CWE-862 8.1 High 2026-10-02
CVE-2026-104465 YesWiki before 4.6.7 Reflected XSS via field Parameter in mail Handler CWE-79 6.1 Medium 2026-10-02
CVE-2026-104464 YesWiki before 4.6.7 SSRF via Bazar abonnements sync actor parameter CWE-918 8.6 High 2026-10-02
CVE-2026-104463 YesWiki before 4.6.7 Unauthenticated SSRF via ActivityPub Inbox CWE-918 7.0 High 2026-10-02
CVE-2026-104462 YesWiki before 4.6.7 SQL Injection via nuagetag tags parameter CWE-89 7.5 High 2026-10-02
CVE-2026-104461 YesWiki before 4.6.7 Stored XSS via Unsanitized SVG Upload in Bazar FileField CWE-79 5.4 Medium 2026-10-02
CVE-2026-104460 YesWiki before 4.6.7 Unauthenticated Blind SQL Injection via newtextsearch CWE-89 7.5 High 2026-10-02
CVE-2026-104458 YesWiki before 4.6.7 SSRF Guard Bypass via IPv6 Transition Addresses CWE-918 6.5 Medium 2026-10-02
CVE-2026-104459 YesWiki before 4.6.7 SSRF via ActivityPub WebFinger actor_handle CWE-918 6.5 Medium 2026-10-02
CVE-2026-104457 YesWiki before 4.6.7 SQL Injection via filtertags filterN parameter CWE-89 8.6 High 2026-10-02
CVE-2026-104455 YesWiki before 4.6.7 Read-ACL Bypass via recentchangesrssplus RSS Action CWE-200 5.3 Medium 2026-10-02
CVE-2026-104456 YesWiki before 4.6.7 Second-Order SQL Injection via ACL Username CWE-89 7.6 High 2026-10-02
CVE-2026-104454 YesWiki before 4.6.7 ReDoS via wakka.php Edit-Preview Endpoint CWE-1333 5.3 Medium 2026-10-02
CVE-2026-104453 YesWiki before 4.6.7 CSRF Tag Deletion via admintag Action CWE-352 5.4 Medium 2026-10-02
CVE-2026-104452 YesWiki before 4.6.7 CSRF Attachment Deletion via filemanager Handler CWE-352 5.4 Medium 2026-10-02
CVE-2026-104451 YesWiki before 4.6.7 CSRF Page Revision Restore via RevisionsHandler CWE-352 4.3 Medium 2026-10-02
CVE-2026-104449 YesWiki before 4.6.7 Unauthenticated Page Overwrite via Bazar id_fiche CWE-639 6.5 Medium 2026-10-02
CVE-2026-104450 YesWiki before 4.6.7 ACL Bypass and Stored XSS via pointimage Action CWE-79 6.5 Medium 2026-10-02
CVE-2026-104448 YesWiki before 4.6.7 CSRF Page Deletion via ajaxdeletepage Handler CWE-352 8.1 High 2026-10-02
CVE-2026-104446 YesWiki before 4.6.7 Unauthenticated Open Mail Relay via Contact Mail Handler CWE-306 6.5 Medium 2026-10-02
CVE-2026-104447 YesWiki before 4.6.7 CSRF Package Deletion via autoupdate UpdateAction CWE-352 7.1 High 2026-10-02
CVE-2026-104445 YesWiki before 4.6.7 Authentication Bypass via ActivityPub Inbox Actor Spoofing CWE-290 8.2 High 2026-10-02
CVE-2026-104443 YesWiki before 4.6.7 Scope Bypass via Triples Delete API CWE-863 8.1 High 2026-10-02

All 64 known CVE vulnerabilities affecting yeswiki with full Chinese analysis, references, and POCs where available.