Cross-Site Request Forgery Vulnerability in YesWiki by YesWiki
CVE-2026-104447

7.1HIGH

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104447?

YesWiki version prior to 4.6.7 is susceptible to a cross-site request forgery vulnerability within the autoupdate UpdateAction feature. This vulnerability enables attackers to send unprotected GET requests that can lead to the deletion of installed packages. An attacker may create a deceptive link containing the action=delete and a package parameter that, when clicked by a logged-in administrator, would result in the unauthorized removal of critical extensions, thereby disrupting the core functionality of the site.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.