| CVE-2026-46670 |
critical |
— |
9.5 |
6d ago |
YesWiki: Unauthenticated SQL Injection |
|
| CVE-2026-41143 |
high |
8.8 |
8.8 |
21d ago |
YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave() |
|
| CVE-2026-34598 |
unknown |
— |
— |
2mo ago |
YesWiki has Persistent Blind XSS at "/?BazaR&vue=consulter" |
|
| CVE-2025-52277 |
unknown |
— |
— |
9mo ago |
YesWiki Cross Site Scripting vulnerability |
|
| CVE-2025-46346 |
unknown |
— |
— |
1y ago |
YesWiki Stored XSS Vulnerability in Comments |
|
| CVE-2025-46347 |
unknown |
— |
— |
1y ago |
YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution |
|
| CVE-2025-46348 |
unknown |
— |
— |
1y ago |
YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download |
|
| CVE-2025-46349 |
unknown |
— |
— |
1y ago |
YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting |
|
| CVE-2025-46350 |
unknown |
— |
— |
1y ago |
Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting |
|
| CVE-2025-46550 |
unknown |
— |
— |
1y ago |
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting |
|
| CVE-2025-46549 |
unknown |
— |
— |
1y ago |
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting |
|
| CVE-2025-31131 |
unknown |
— |
— |
1y ago |
Yeswiki Path Traversal vulnerability allows arbitrary read of files |
|
| CVE-2025-24019 |
unknown |
— |
— |
1y ago |
Authenticated arbitrary file deletion in YesWiki |
|
| CVE-2025-24018 |
unknown |
— |
— |
1y ago |
Authenticated Stored XSS in YesWiki |
|
| CVE-2025-24017 |
unknown |
— |
— |
1y ago |
Unauthenticated DOM Based XSS in YesWiki |
|
| CVE-2024-51478 |
unknown |
— |
— |
2y ago |
YesWiki Uses a Broken or Risky Cryptographic Algorithm |
|
| CVE-2021-43091 |
unknown |
— |
— |
4y ago |
SQL Injection in Yeswiki |
|