CVE-2025-52277: Yeswiki

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted payload to the meta configuration robots field

Affected products

  • Yeswiki Yeswiki: version 4.5.4 only

Published 2025-09-09. Last modified 2026-07-05.