Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-46350


YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability may also allow attackers to deface the website or embed malicious content. This issue has been patched in version 4.5.4.


Published

2025-04-29T18:15:44.950

Last Modified

2025-05-09T13:57:36.823

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 3.5 (LOW)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application yeswiki yeswiki < 4.5.4 Yes

References