Stored and Blind XSS Vulnerability in YesWiki Wiki System
CVE-2026-34598

7.1HIGH

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 April 2026

What is CVE-2026-34598?

YesWiki, a PHP-based wiki system, is susceptible to a stored and blind Cross-Site Scripting (XSS) vulnerability. This issue allows unauthorized users to inject malicious JavaScript code through the form title field, which is saved in the backend database. When any user accesses the affected page, the injected script gets executed in their browser, potentially compromising user data and privacy. The vulnerability has been addressed in version 4.6.0, and users are strongly advised to upgrade to this version or later to mitigate security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

yeswiki < 4.6.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.