CVE-2025-46348 is a critical unauthenticated backup download vulnerability affecting YesWiki versions prior to 4.5.4. Attackers can exploit this flaw over the network with low complexity to create and download site backups due to predictable filenames, leading to potential denial of service by filling disk space or compromise of sensitive information. With a CVSS score of 9.8 (CRITICAL), the impact includes high confidentiality, integrity, and availability risks. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.4CPE matchmatch criteria | cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.