CVE-2025-46549 is a reflected cross-site scripting (XSS) vulnerability in YesWiki, a PHP-based wiki system, affecting versions prior to 4.5.4. An attacker can exploit this by tricking an authenticated user into clicking a malicious link, enabling cookie theft and session hijacking. This medium-severity vulnerability (CVSS 6.1) has a low attack complexity and can lead to data compromise, website defacement, or malicious content injection. While not currently in CISA's KEV catalog or actively exploited, a Nuclei template exists for detection, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.4CPE matchmatch criteria | cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.