Description
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action that allows attackers to delete tag associations by luring administrators to crafted GET links. Attackers can supply a wide id range in the delete_tag parameter via top-level navigation, carrying the SameSite=Lax admin cookie, to bulk-delete tag triples.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized deletion of tag associations
Action: Patch
AI Analysis

Impact

YesWiki before version 4.6.7 contains a CSRF weakness in the admintag action that lets an attacker delete tag associations by luring an administrator to click a crafted GET link. The flaw allows the attacker to supply a broad range of tag identifiers, thereby bulk‑deleting tag triples that link content to categories or metadata. The vulnerability is a classic cross‑site request forgery, coded as CWE‑352, and results in integrity loss of the site’s tagging system without affecting confidentiality or granting code execution.

Affected Systems

YesWiki application (vendor YesWiki:yeswiki) – all releases prior to 4.6.7 are vulnerable. Any deployment of YesWiki 4.6.6 or earlier must be considered at risk.

Risk and Exploitability

The CVSS score of 5.3 places it in the moderate range, and the lack of an EPSS score suggests that exploitation probability is uncertain but not negligible. Because it affects only administrators, the impact is localized to those accounts, yet the deletion of tags can break content linking across the entire site. The flaw is not currently represented in CISA’s KEV catalog, so the urgency is lower than a widely exploited vulnerability, but any organisation managing content integrity should treat it as high priority.

Generated by OpenCVE AI on October 2, 2026 at 12:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YesWiki to version 4.6.7 or later, which fixes the CSRF vulnerability in the admintag action.
  • If an upgrade cannot be performed immediately, restrict the admintag action by removing it from public URLs or limiting its use to trusted administrative consoles.
  • Implement standard CSRF protection such as anti‑CSRF tokens or require POST requests for deletion actions to prevent unauthorised tag removal from crafted GET links.

Generated by OpenCVE AI on October 2, 2026 at 12:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action that allows attackers to delete tag associations by luring administrators to crafted GET links. Attackers can supply a wide id range in the delete_tag parameter via top-level navigation, carrying the SameSite=Lax admin cookie, to bulk-delete tag triples.
Title YesWiki before 4.6.7 CSRF Tag Deletion via admintag Action
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-352
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:24.392Z

Reserved: 2026-10-02T00:53:58.504Z

Link: CVE-2026-104453

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:17.003

Modified: 2026-10-02T12:17:17.117

Link: CVE-2026-104453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:30:05Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)