Description
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page revisions through GET requests lacking CSRF token validation. Attackers can lure write-capable users into a top-level navigation with the restoreRevisionId parameter, silently overwriting current page content with stale or vandalized revisions.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Content Modification
Action: Immediate Patch
AI Analysis

Impact

YesWiki versions prior to 4.6.7 contain a cross‑site request forgery flaw in the RevisionsHandler that allows an attacker to force a user to send a GET request with a restoreRevisionId parameter. The request bypasses CSRF token validation and silently restores a previously saved page revision, overwriting the current page contents. This flaw permits stealthy content modification, compromising data integrity on the site.

Affected Systems

The vulnerability affects the YesWiki CMS when running any version earlier than 4.6.7. Administrators using older releases should review their deployment, as the affected component is the RevisionsHandler module within the YesWiki codebase.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and no EPSS score is available for this entry. Although the vulnerability is not listed in the CISA KEV catalog, the CSRF nature of the flaw means that exploitation requires a social‑engineering step, such as luring a write‑capable user onto a malicious link or navigation item. Once a user follows the crafted link, the page would be overwritten with an older revision without notification.

Generated by OpenCVE AI on October 2, 2026 at 12:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YesWiki to version 4.6.7 or later to receive the CSRF fix
  • Configure the application to disallow RESTORE actions via GET requests, enforcing POST-only methods for all state‑changing operations
  • Apply comprehensive CSRF protections, such as matching tokens on all non‑idempotent requests, or use a security module to block unsolicited GET requests to the restore endpoint

Generated by OpenCVE AI on October 2, 2026 at 12:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page revisions through GET requests lacking CSRF token validation. Attackers can lure write-capable users into a top-level navigation with the restoreRevisionId parameter, silently overwriting current page content with stale or vandalized revisions.
Title YesWiki before 4.6.7 CSRF Page Revision Restore via RevisionsHandler
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-352
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T13:34:35.216Z

Reserved: 2026-10-02T00:53:58.504Z

Link: CVE-2026-104451

cve-icon Vulnrichment

Updated: 2026-10-02T13:34:31.066Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:16.673

Modified: 2026-10-02T14:17:08.480

Link: CVE-2026-104451

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T12:45:19Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)