Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

yeswiki — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in yeswiki, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities affecting YesWiki, an open-source wiki platform designed for collaborative web content management. It aggregates known weaknesses associated with this specific product, focusing on issues reported across various release versions and patches. The collection covers vulnerability data spanning multiple years, capturing both historical findings and recent disclosures to provide a comprehensive view of the product’s security landscape over time. Here, users can track the vendor's security advisories to stay informed about critical updates and remediation efforts. Readers are also able to understand specific weakness classes that have impacted YesWiki, such as injection flaws or cross-site scripting issues, by examining detailed descriptions and affected components. Furthermore, this resource allows for looking up the product's vulnerability history, enabling developers and system administrators to review past incidents, assess potential risks in legacy versions, and prioritize mitigation strategies based on the frequency and severity of reported bugs. The data is organized to facilitate easy navigation through different categories of threats, helping stakeholders maintain a secure deployment environment. By centralizing this information, the page serves as a reference point for auditing systems, understanding the evolution of security practices in YesWiki, and identifying patterns in how vulnerabilities are discovered and addressed by the community and maintainers. This approach ensures transparency and supports informed decision-making regarding software upgrades and configuration changes.

Vendor: YesWiki

CVE IDTitleCVSSSeverityPublished
CVE-2026-52778 YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of Service (DoS) CWE-94 9.8 Critical2026-06-08
CVE-2026-41143 YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave() CWE-89 8.8 High2026-05-07
CVE-2026-34598 YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter" CWE-79 6.1AIMediumAI2026-04-02
CVE-2025-46550 Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting CWE-79 4.3 Medium2025-04-29
CVE-2025-46549 Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting CWE-79 4.3 Medium2025-04-29
CVE-2025-46348 YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download CWE-287 10.0 Critical2025-04-29
CVE-2025-46350 Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting CWE-79 3.5 Low2025-04-29
CVE-2025-46349 YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting CWE-79 7.6 High2025-04-29
CVE-2025-46347 YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution CWE-116 8.8AIHighAI2025-04-29
CVE-2025-46346 YesWiki Vulnerable to Stored XSS in Comments CWE-79 5.4AIMediumAI2025-04-29
CVE-2025-31131 Path Traversal allowing arbitrary read of files in Yeswiki CWE-22 8.6 High2025-04-01
CVE-2025-24019 YesWiki vulnerable to authenticated arbitrary file deletion CWE-22 7.1 High2025-01-21
CVE-2025-24018 YesWiki Vulnerable to Authenticated Stored XSS CWE-79 7.6 High2025-01-21
CVE-2025-24017 YesWiki Vulnerable to Unauthenticated DOM Based XSS CWE-79 7.6 High2025-01-21
CVE-2024-51478 Use of a Broken or Risky Cryptographic Algorithm in YesWiki CWE-327 9.9 Critical2024-10-31

All 15 known CVE vulnerabilities affecting yeswiki with full Chinese analysis, references, and POCs where available.