Cross-Site Request Forgery Vulnerability in YesWiki by YesWiki
CVE-2026-104453
5.3MEDIUM
What is CVE-2026-104453?
YesWiki versions prior to 4.6.7 are susceptible to a cross-site request forgery (CSRF) vulnerability affecting the admintag action. Attackers can exploit this flaw by crafting specific GET links that trick administrators into performing unwanted tag deletion. By supplying a wide range of IDs in the delete_tag parameter while retaining the SameSite=Lax admin cookie, malicious actors can execute bulk deletions of tag associations, compromising the integrity of the site's tagging system.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
