Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-46549


YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability may also allow attackers to deface the website or embed malicious content. This issue has been patched in version 4.5.4.


Published

2025-04-29T21:15:52.270

Last Modified

2025-05-09T13:59:06.793

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application yeswiki yeswiki < 4.5.4 Yes

References