Vulnerabilities in YesWiki
16 resultsVexday analysis
O YesWiki acumula 15 vulnerabilidades catalogadas, predominantemente injeção XSS (CWE-79), com 3 casos críticos, mas nenhuma sob exploração ativa até o momento. O ritmo de descobertas é moderado (2 nos últimos 90 dias), sugerindo risco contenível para quem usa versões atualizadas, embora o histórico de flaws de validação de entrada exija atenção contínua.
CVE-2025-31131HIGHPath Traversal allowing arbitrary read of files in YeswikiEPSS 5.4%CVE-2026-46670CRITICALYesWiki: Unauthenticated SQL InjectionEPSS 1.7%CVE-2025-46347MEDIUMYesWiki Remote Code Execution via Arbitrary PHP File Write and ExecutionEPSS 1.0%CVE-2025-46348CRITICALYesWiki Vulnerable to Unauthenticated Site Backup Creation and DownloadEPSS 0.6%CVE-2025-46349HIGHYesWiki Vulnerable to Unauthenticated Reflected Cross-site ScriptingEPSS 0.6%CVE-2025-24019HIGHYesWiki vulnerable to authenticated arbitrary file deletionEPSS 0.6%CVE-2026-52778CRITICALYesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of Service (DoS)EPSS 0.6%CVE-2025-46550MEDIUMYeswiki Vulnerable to Unauthenticated Reflected Cross-site ScriptingEPSS 0.5%CVE-2025-46549MEDIUMYeswiki Vulnerable to Unauthenticated Reflected Cross-site ScriptingEPSS 0.5%CVE-2025-24018HIGHYesWiki Vulnerable to Authenticated Stored XSSEPSS 0.4%CVE-2024-51478CRITICALUse of a Broken or Risky Cryptographic Algorithm in YesWikiEPSS 0.4%CVE-2025-24017HIGHYesWiki Vulnerable to Unauthenticated DOM Based XSSEPSS 0.4%CVE-2026-41143HIGHYesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()EPSS 0.3%CVE-2025-46346MEDIUMYesWiki Vulnerable to Stored XSS in CommentsEPSS 0.3%CVE-2025-46350LOWYeswiki Vulnerable to Authenticated Reflected Cross-site ScriptingEPSS 0.3%CVE-2026-34598HIGHYesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter"EPSS 0.2%