Stored and Blind XSS Vulnerability in YesWiki Wiki System
CVE-2026-34598
7.1HIGH
What is CVE-2026-34598?
YesWiki, a PHP-based wiki system, is susceptible to a stored and blind Cross-Site Scripting (XSS) vulnerability. This issue allows unauthorized users to inject malicious JavaScript code through the form title field, which is saved in the backend database. When any user accesses the affected page, the injected script gets executed in their browser, potentially compromising user data and privacy. The vulnerability has been addressed in version 4.6.0, and users are strongly advised to upgrade to this version or later to mitigate security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
yeswiki < 4.6.0
