CVE-2025-31131: Yeswiki
High severity, CVSS 7.5. EPSS: 5.5% chance of exploitation in the next 30 days.
YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability is fixed in 4.5.2.
Affected products
- Yeswiki Yeswiki: before 4.5.2 (fixed in 4.5.2)
Published 2025-04-01. Last modified 2026-06-17.