Cross-Site Request Forgery in YesWiki Affects Page Deletion Functionality
CVE-2026-104448

7.2HIGH

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104448?

YesWiki versions prior to 4.6.7 are vulnerable to a cross-site request forgery (CSRF) flaw in the ajaxdeletepage handler. This vulnerability allows attackers to craft malicious links that, when clicked by an authenticated administrator or page owner, can result in the unauthorized deletion of arbitrary pages. This action can lead to the removal of crucial content, including access control lists (ACLs), links, comments, and other related data, without any proper validation of the user's intent. It is essential for users of affected versions to upgrade to the latest release to mitigate this risk.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.