Stored and Blind XSS Vulnerability in YesWiki Wiki System
CVE-2026-34598
7.1HIGH
What is CVE-2026-34598?
YesWiki, a PHP-based wiki system, is susceptible to a stored and blind Cross-Site Scripting (XSS) vulnerability. This issue allows unauthorized users to inject malicious JavaScript code through the form title field, which is saved in the backend database. When any user accesses the affected page, the injected script gets executed in their browser, potentially compromising user data and privacy. The vulnerability has been addressed in version 4.6.0, and users are strongly advised to upgrade to this version or later to mitigate security risks.
Affected Version(s)
yeswiki < 4.6.0
