Cross-Site Request Forgery Vulnerability in YesWiki Platform
CVE-2026-104451

5.3MEDIUM

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104451?

The YesWiki platform prior to version 4.6.7 is susceptible to a cross-site request forgery vulnerability within the RevisionsHandler component. This vulnerability enables an attacker to exploit the system by RESToring outdated page versions without proper validation of the CSRF token. By impersonating a legitimate user, an attacker can craft a malicious link containing the restoreRevisionId parameter, tricking the user into revisiting the navigation and resulting in the unintended replacement of current content with outdated or potentially harmful revisions.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.