Loading market data...
← Back to CVE feed

CVE-2026-104455

MEDIUM CVSS 5.3 View on NVD ↗

Description

YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content via the recentchangesrssplus RSS action. Attackers can request the xml method of a page hosting the action to retrieve 500-character body excerpts of every latest page, including read-restricted drafts and notes.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Oct 02, 2026 12:17 UTC Modified: Oct 02, 2026 14:17 UTC