Loading market data...
← Back to CVE feed

CVE-2026-104468

MEDIUM CVSS 4.8 View on NVD ↗

Description

YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or browser history can submit a new password through checkEmailKey() and take over accounts.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Published: Oct 02, 2026 12:17 UTC Modified: Oct 02, 2026 15:17 UTC