Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yeswiki MEDIUM 6.1
CVE-2026-34598

YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form title field. A malicious att…

Fix: 4.6.0+
Fix from $1,600 2026-04-02
Yeswiki MEDIUM 6.1
CVE-2025-52277

Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted payload to the meta configurati…

No fix yet
Fix from $1,600 2025-09-09
Yeswiki CRITICAL 9.8
CVE-2025-46348

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authen…

Fix: 4.5.4+
Fix from $2,300 2025-04-29
Yeswiki MEDIUM 6.1
CVE-2025-46549

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an…

Fix: 4.5.4+
Fix from $1,600 2025-04-29
Yeswiki MEDIUM 6.1
CVE-2025-46550

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scr…

Fix: 4.5.4+
Fix from $1,600 2025-04-29
Yeswiki CRITICAL 9.8
CVE-2025-46347

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used to …

Fix: 4.5.4+
Fix from $2,300 2025-04-29
Yeswiki MEDIUM 6.1
CVE-2025-46349

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability a…

Fix: 4.5.4+
Fix from $1,600 2025-04-29
Yeswiki MEDIUM 5.4
CVE-2025-46346

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, a stored cross-site scripting (XSS) vulnerability was discovered in the application’…

Fix: 4.5.4+
Fix from $1,600 2025-04-29
Yeswiki HIGH 7.5
CVE-2025-31131EPSS 5%

YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on …

Fix: 4.5.2+
Fix from $1,950 2025-04-01
Yeswiki HIGH 7.1
CVE-2025-24019

YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for any authenticated user, through the use of the fil…

Fix: 4.5.0+
Fix from $1,950 2025-01-21
Yeswiki MEDIUM 5.4
CVE-2025-24018

YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for an authenticated user with rights to edit/create a…

Fix: 4.5.0+
Fix from $1,600 2025-01-21
Yeswiki MEDIUM 6.1
CVE-2025-24017

YesWiki is a wiki system written in PHP. Versions up to and including 4.4.5 are vulnerable to any end-user crafting a DOM based XSS on all of YesWiki…

Fix: 4.5.0+
Fix from $1,600 2025-01-21
Yeswiki CRITICAL 9.1
CVE-2024-51478

YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset k…

Fix: 4.4.5+
Fix from $2,300 2024-10-31
Yeswiki HIGH 7.5
CVE-2021-43091

An SQL Injection vlnerability exits in Yeswiki doryphore 20211012 via the email parameter in the registration form.

Patch available
Fix from $1,950 2022-03-25
Cercopitheque CRITICAL 9.8
CVE-2018-13045

SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands …

Fix: after 2018-06-19-1
Fix from $2,300 2019-01-02
Yeswiki CRITICAL 9.8
CVE-2018-1000641

YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in Unserialising user entered parameter in i18n.inc.php that ca…

Patch available
Fix from $2,300 2018-08-20