CVE-2018-1000641: Yeswiki

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in Unserialising user entered parameter in i18n.inc.php that can result in execution of code, disclosure of information.

Affected products

  • Yeswiki Yeswiki: version 2012-10-22-1 only; version 2013-10-17-1 only; version 2016-03-17-1 only

Published 2018-08-20. Last modified 2026-06-17.