VYPR

Yeswiki

by Yeswiki

Source repositories

CVEs (31)

  • CVE-2025-52277MedSep 9, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted payload to the meta configuration robots field

  • CVE-2026-52762HigSep 5, 2026
    risk 0.39cvss —epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic template feature that can be escalated to confirmed Remote Code Execution (RCE). An authenticated administrator…

  • CVE-2025-24019HigJan 21, 2025
    risk 0.39cvss 7.1epss 0.01

    YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for any authenticated user, through the use of the filemanager to delete any file owned by the user running the FastCGI Process Manager (FPM) on the host without any limitation on the…

  • CVE-2026-52763MedSep 5, 2026
    risk 0.35cvss 6.5epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter spaces. A whitelist validates only the URL form against ['day','week','month']. The action-argument form…

  • CVE-2026-52774MedSep 5, 2026
    risk 0.33cvss 6.1epss 0.01

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using strip_tags() only. Because strip_tags() does not escape double quotes, an attacker can break out of the attribute value,…

  • CVE-2026-52773MedSep 5, 2026
    risk 0.33cvss 6.1epss 0.00

    YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coerces malformed DATETIME strings, an…

  • CVE-2026-52772MedSep 5, 2026
    risk 0.29cvss 5.5epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders. This issue has been patched in version 4.6.6.

  • CVE-2025-46346MedApr 29, 2025
    risk 0.28cvss 5.4epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.5.4, a stored cross-site scripting (XSS) vulnerability was discovered in the application’s comments feature. This issue allows a malicious actor to inject JavaScript payloads that are stored and later executed in the…

  • CVE-2025-46550MedApr 29, 2025
    risk 0.21cvss 4.3epss 0.01

    YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them…

  • CVE-2025-46549MedApr 29, 2025
    risk 0.21cvss 4.3epss 0.01

    YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session.…

  • CVE-2025-46350LowApr 29, 2025
    risk 0.16cvss 3.5epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session.…

Page 2 of 2