CVE-2026-104454: Yeswiki

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an O(n^2) markdown-link regex. Unauthenticated attackers can submit a small crafted body of bracket characters to the page-edit preview endpoint to pin PHP-FPM workers and saturate the pool.

Affected products

  • Yeswiki Yeswiki: before 4.6.7 (fixed in 4.6.7)

Published 2026-10-02. Last modified 2026-10-02.