Loading market data...
← Back to CVE feed

CVE-2026-104448

HIGH CVSS 8.1 View on NVD ↗

Description

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback parameter without checking a CSRF token. Attackers can lure a logged-in administrator or page owner to a crafted link to delete arbitrary pages along with their ACLs, links, triples, comments and referrers.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Published: Oct 02, 2026 12:17 UTC Modified: Oct 02, 2026 15:17 UTC