Cross-Site Request Forgery in YesWiki Affects Page Deletion Functionality
CVE-2026-104448
7.2HIGH
What is CVE-2026-104448?
YesWiki versions prior to 4.6.7 are vulnerable to a cross-site request forgery (CSRF) flaw in the ajaxdeletepage handler. This vulnerability allows attackers to craft malicious links that, when clicked by an authenticated administrator or page owner, can result in the unauthorized deletion of arbitrary pages. This action can lead to the removal of crucial content, including access control lists (ACLs), links, comments, and other related data, without any proper validation of the user's intent. It is essential for users of affected versions to upgrade to the latest release to mitigate this risk.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
