Cross-Site Request Forgery Vulnerability in YesWiki by YesWiki
CVE-2026-104447
7.1HIGH
What is CVE-2026-104447?
YesWiki version prior to 4.6.7 is susceptible to a cross-site request forgery vulnerability within the autoupdate UpdateAction feature. This vulnerability enables attackers to send unprotected GET requests that can lead to the deletion of installed packages. An attacker may create a deceptive link containing the action=delete and a package parameter that, when clicked by a logged-in administrator, would result in the unauthorized removal of critical extensions, thereby disrupting the core functionality of the site.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
