Description
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback parameter without checking a CSRF token. Attackers can lure a logged-in administrator or page owner to a crafted link to delete arbitrary pages along with their ACLs, links, triples, comments and referrers.
Published: 2026-10-02
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Data Loss via CSRF
Action: Patch
AI Analysis

Impact

YesWiki on any version prior to 4.6.7 accepts GET requests to the ajaxdeletepage handler that include a jsonp_callback parameter without validating a CSRF token. This flaw allows an attacker to permanently delete a targeted page, its access control lists, links, triples, comments and referrers when a logged‑in administrator or page owner is tricked into visiting a crafted URL. The data lost can be critical to the organization and the removal cannot be undone without a backup.

Affected Systems

The vulnerability affects the YesWiki content management system, specifically all releases before 4.6.7. The product is maintained by the YesWiki community and impacts versions 4.6.6 and older.

Risk and Exploitability

The CVSS score of 7.2 indicates a high impact vulnerability that can be exploited through a CSRF attack vector. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog, but the lack of a mitigation token means any authenticated user can be victimized by a simple click‑through phishing link. The risk is significant for sites with active administrators and page owners, and immediate remediation is advised.

Generated by OpenCVE AI on October 2, 2026 at 13:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YesWiki to version 4.6.7 or later to eliminate the CSRF flaw.
  • If upgrading immediately is not feasible, restrict GET access to the ajaxdeletepage handler—e.g., via web‑server rewrites or by disabling the route in the application configuration until a patch can be applied.
  • After applying the patch, review page ownership and ACL configurations for any unintended changes and restore missing content from backups if necessary.

Generated by OpenCVE AI on October 2, 2026 at 13:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback parameter without checking a CSRF token. Attackers can lure a logged-in administrator or page owner to a crafted link to delete arbitrary pages along with their ACLs, links, triples, comments and referrers.
Title YesWiki before 4.6.7 CSRF Page Deletion via ajaxdeletepage Handler
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-352
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T14:52:40.749Z

Reserved: 2026-10-02T00:53:03.852Z

Link: CVE-2026-104448

cve-icon Vulnrichment

Updated: 2026-10-02T14:52:20.339Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:16.163

Modified: 2026-10-02T15:17:07.150

Link: CVE-2026-104448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:45:17Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)