Reflected Cross-Site Scripting Vulnerability in YesWiki PHP System
CVE-2025-46550
What is CVE-2025-46550?
YesWiki, a wiki system developed in PHP, is susceptible to a reflected cross-site scripting (XSS) vulnerability through its /?BazaR endpoint and the idformulaire parameter. This issue allows attackers to exploit the vulnerability by persuading authenticated users to click on malicious links. When this occurs, attackers can steal session cookies, potentially leading to session hijacking. The vulnerability also poses risks of website defacement and the injection of malicious content. Users are urged to upgrade to version 4.5.4, which includes necessary patches to mitigate these security threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
yeswiki < 4.5.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
