CVE-2026-104453: Yeswiki

Medium severity, CVSS 5.4. EPSS: 0.1% chance of exploitation in the next 30 days.

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action that allows attackers to delete tag associations by luring administrators to crafted GET links. Attackers can supply a wide id range in the delete_tag parameter via top-level navigation, carrying the SameSite=Lax admin cookie, to bulk-delete tag triples.

Affected products

  • Yeswiki Yeswiki: before 4.6.7 (fixed in 4.6.7)

Published 2026-10-02. Last modified 2026-10-06.