yeswiki
Web & CMS Pluginsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting yeswiki.
- CVE-2026-46670YesWiki: Unauthenticated SQL Injection9.8
- CVE-2026-52778YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of Service (DoS)9.8
- CVE-2026-41143YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()8.8
- CVE-2026-34598YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter"6.1
- CVE-2025-52277Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted payload to the meta configuration robots field6.1
- CVE-2025-46550Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting4.3
- CVE-2025-46549Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting4.3
- CVE-2025-46348YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download10.0
- CVE-2025-46350Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting3.5
- CVE-2025-46349YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting7.6
- CVE-2025-46347YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution9.8
- CVE-2025-46346YesWiki Vulnerable to Stored XSS in Comments5.4
- CVE-2025-31131Path Traversal allowing arbitrary read of files in Yeswiki8.6
- CVE-2025-24019YesWiki vulnerable to authenticated arbitrary file deletion7.1
- CVE-2025-24018YesWiki Vulnerable to Authenticated Stored XSS7.6