Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mrflos

#34189of 53,624
7.6Total CVSS
Vulnerabilities · 1
PT-2025-18196
7.6
2025-04-29
Yeswiki · Yeswiki · CVE-2025-46349
**Name of the Vulnerable Software and Affected Versions** YesWiki versions prior to 4.5.4 **Description** The issue is related to reflected XSS in the file upload form, allowing malicious unauthenticated users to create links that can perform arbitrary actions when clicked by a victim. **Recommendations** For versions prior to 4.5.4, update to version 4.5.4 to resolve the issue. As a temporary workaround, consider restricting access to the file upload form until the update is applied.