CRITICAL10.0CVE-2025-46348YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download from 0, < 4.5.4
CRITICAL9.9CVE-2024-51478YesWiki Uses a Broken or Risky Cryptographic Algorithm from 0, < 4.4.5
CRITICAL9.8CVE-2026-52778YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service from 0, < 4.6.6
CRITICAL9.8YesWiki: Unauthenticated SQL Injection
from 0, < 4.6.4
CRITICAL9.1YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action
from 0, < 4.6.6
HIGH8.8YesWiki has Authenticated SQL Injection via ReactionManager
from 0, < 4.6.6
HIGH8.8YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()
from 0, < 4.6.1
HIGH8.6Yeswiki Path Traversal vulnerability allows arbitrary read of files
from 0, < 4.5.2
HIGH8.3YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)
>= 4.2.0, < 4.6.6
HIGH8.3YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`
>= 4.6.2, < 4.6.6
HIGH8.2YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`
>= 4.6.2, < 4.6.6
HIGH7.6YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
from 0, <= 4.5.3
HIGH7.6Authenticated Stored XSS in YesWiki
from 0, < 4.5.0
HIGH7.6Unauthenticated DOM Based XSS in YesWiki
from 0, < 4.5.0
HIGH7.5YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filters
from 0, < 4.6.6
HIGH7.5SQL Injection in Yeswiki
from 0, < 4.1.0
HIGH7.1Authenticated arbitrary file deletion in YesWiki
from 0, < 4.5.0
MEDIUM6.5YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB read
from 0, < 4.6.6
MEDIUM6.1YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes
from 0, < 4.6.6
MEDIUM6.1YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php`
>= 4.1.0, < 4.6.6
MEDIUM6.1YesWiki Cross Site Scripting vulnerability
from 0, <= 4.5.4
MEDIUM5.5YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html'))
from 0, < 4.6.6
MEDIUM5.3Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
from 0, < 4.5.4
MEDIUM5.3Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
from 0, < 4.5.4
LOW3.8Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting
from 0, < 4.5.4
—YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize
from 0, < 4.6.6
—YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
from 0, < 4.6.6
—YesWiki has Persistent Blind XSS at "/?BazaR&vue=consulter"
from 0, < 4.6.0
—YesWiki Stored XSS Vulnerability in Comments
from 0, < 4.5.4
—YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution
from 0, < 4.5.4