Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-51478

25
FAUCET Score

CVE-2024-51478 is a critical vulnerability affecting YesWiki versions prior to 4.4.5, stemming from the use of a weak cryptographic algorithm and hard-coded salt for password reset keys. This flaw allows an unauthenticated attacker to recover and exploit these keys to reset any user's password. With a CVSS score of 9.1, it presents a high risk of complete compromise of confidentiality and integrity, requiring no user interaction or complex attack conditions. While no active exploitation, public exploit code, or significant community discussion has been observed, the vulnerability is patched in YesWiki 4.4.5, and immediate upgrade is recommended.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.4.5CPE matchmatch criteria
cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
5.3
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.37%
Probability of exploitation in next 30 days
EPSS Percentile
29.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 7th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: yeswiki/yeswikiFixed in: 4.4.5
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-4fvx-h823-38v3high

YesWiki Uses a Broken or Risky Cryptographic Algorithm

Oct 31, 2024

References

github.com / YesWiki/yeswiki/commit/b5a8f93b87720d5d5f033a4b3a131ce0fb621dbc
Patch
github.com / YesWiki/yeswiki/commit/e1285709f6f6a2277bd0075acf369f33cefd78f7
Patch
github.com / YesWiki/yeswiki/security/advisories/GHSA-4fvx-h823-38v3
ExploitVendor Advisory