Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
82 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.28% | — | YeswikiAI | 2/10/2026 | 6/10/2026 | YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via the Bazar entry-creation flow. Attackers can submit a crafted entry with an attacker-controlled id_fiche matching an existing… | |
| Aplazada | Alta (7.2) | 0.16% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback parameter without checking a CSRF token. Attackers can lure a logged-in administrator or page owner to a crafted link to delete arbitrary… | |
| Aplazada | Alta (7.1) | 0.13% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed packages via unprotected GET requests. Attackers can lure a logged-in administrator to a crafted link with action=delete and a package parameter to remove extensions like… | |
| Aplazada | Media (6.9) | 0.43% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. Attackers can POST an XMLHttpRequest to the mail handler without field or type parameters, supplying arbitrary recipient, sender, subject and body… | |
| Aplazada | Alta (8.8) | 0.40% | — | YeswikiAI | 2/10/2026 | 6/10/2026 | YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to… | |
| Aplazada | Alta (7.1) | 0.27% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a… | |
| Aplazada | Alta (7.2) | 0.36% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the… | |
| Aplazada | Media (6.9) | 0.32% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication action through the render handler's content parameter. Attackers can target internal hosts and ports, read back fetched feed content… | |
| Aplazada | Media (6.9) | 0.29% | — | YeswikiAI | 2/10/2026 | 6/10/2026 | YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary hosts and ports via the {{valeur}} action's url parameter. Attackers can submit the action through the content parameter of handlers/page/render.php to probe… | |
| Aplazada | Media (6.9) | 0.29% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side requests via the idtypeannonce parameter of /api/entries/bazarlist. Because isValidURL() always returns true, attackers can supply internal URLs fetched by curl in… | |
| Aplazada | Alta (7.1) | 0.34% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recovery page without rate limiting to identify valid accounts for… | |
| Aplazada | Alta (8.7) | 0.30% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. Unauthenticated or unprivileged attackers can embed these actions with a chosen tag or page name to disclose the names and… | |
| Aplazada | Crítica (9.4) | 0.28% | — | YeswikiAI | 5/9/2026 | 8/9/2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6. | |
| Aplazada | Alta (8.8) | 0.48% | — | YeswikiAI | 5/9/2026 | 8/9/2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary SQL via the {idreaction} and {id} URL path parameters. The parameters are… | |
| Aplazada | Media (6.1) | 0.66% | 💥 Exploit | YeswikiAI | 5/9/2026 | 8/9/2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using strip_tags() only. Because strip_tags() does not escape double quotes, an attacker can break out of the attribute value, inject an event handler such as onmouseover,… | |
| Aplazada | Media (6.1) | 0.59% | 💥 Exploit | YeswikiAI | 5/9/2026 | 8/9/2026 | YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coerces malformed DATETIME strings, an attacker can append HTML or JavaScript to a… | |
| Aplazada | Media (5.5) | 0.34% | — | YeswikiAI | 5/9/2026 | 9/9/2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders. This issue has been patched in version 4.6.6. | |
| Aplazada | Alta (8.3) | 0.51% | — | YeswikiAI | 5/9/2026 | 8/9/2026 | YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' query without escaping. The page tag is attacker-controlled — the POST /api/pages/{tag} API accepts… | |
| Aplazada | Alta (7.5) | 0.47% | — | YeswikiAI | 5/9/2026 | 8/9/2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query / queries filters. For Bazar fields whose value structure is numeric, YesWiki escapes the attacker-controlled filter value but inserts it into SQL… | |
| Aplazada | Alta (8.3) | 0.49% | — | YeswikiAI | 5/9/2026 | 8/9/2026 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - accepts an HTTP Signature header whose keyId parameter is a URL. HttpSignatureService::verifySignature() parses the header and immediately makes a… | |
| Aplazada | Alta (8.2) | 0.35% | — | YeswikiAI | 5/9/2026 | 8/9/2026 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ... }. PHP's openssl_verify has four possible return values: 1, 0, -1, and "false".… | |
| Aplazada | Crítica (9.1) | 0.58% | — | YeswikiAI | 5/9/2026 | 9/9/2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion… | |
| Aplazada | Media (6.5) | 0.38% | — | YeswikiAI | 5/9/2026 | 8/9/2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter spaces. A whitelist validates only the URL form against ['day','week','month']. The action-argument form takes the else branch with no validation,… | |
| Aplazada | Alta (7.1) | 0.78% | — | YeswikiAI | 5/9/2026 | 8/9/2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic template feature that can be escalated to confirmed Remote Code Execution (RCE). An authenticated administrator can place arbitrary Twig expressions into… | |
| Aplazada | Crítica (9.8) | 2.0% | 💥 Exploit | YeswikiAI | 11/8/2026 | 9/9/2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including… |