Cross-Site Request Forgery Vulnerability in YesWiki Platform
CVE-2026-104451
5.3MEDIUM
What is CVE-2026-104451?
The YesWiki platform prior to version 4.6.7 is susceptible to a cross-site request forgery vulnerability within the RevisionsHandler component. This vulnerability enables an attacker to exploit the system by RESToring outdated page versions without proper validation of the CSRF token. By impersonating a legitimate user, an attacker can craft a malicious link containing the restoreRevisionId parameter, tricking the user into revisiting the navigation and resulting in the unintended replacement of current content with outdated or potentially harmful revisions.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
