Insufficient Session Expiration in YesWiki by YesWiki
CVE-2026-104468
6.3MEDIUM
What is CVE-2026-104468?
YesWiki versions prior to 4.6.7 are susceptible to an insufficient session expiration vulnerability, which permits attackers to reuse old password reset links. The absence of expiry timestamps on tokens allows unauthorized individuals, with access to unused reset URLs found in mailboxes, logs, backups, or browser history, to submit a new password via the checkEmailKey() function, potentially leading to unauthorized account access.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
