CVE-2024-51478: Yeswiki
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.
Affected products
- Yeswiki Yeswiki: before 4.4.5 (fixed in 4.4.5)
Published 2024-10-31. Last modified 2026-06-17.