Yeswiki is a modestly represented wiki and collaboration platform with a narrow product portfolio but a position among more prominent vendors in the vulnerability landscape. Its vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit code; the exposure recurs across products such as Yeswiki and Cercopitheque and clusters around web-application weakness classes including cross-site scripting, path traversal, SQL injection, untrusted deserialization, and improper authentication. Defenders should treat this vendor's advisories as high-priority for any instances exposed to untrusted input; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yeswiki over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-31131HIGH YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability | Apr 1, 2025 | 7.5 | 46 | NO | YES |
CVE-2018-13045CRITICAL SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter. | Jan 2, 2019 | 9.8 | 41 | NO | YES |
CVE-2018-1000641CRITICAL YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in Unserialising user entered parameter in i18n.inc.php that can result in execution of code, | Aug 20, 2018 | 9.8 | 30 | NO | NO |
CVE-2025-46348CRITICAL YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are crea | Apr 29, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-46349MEDIUM YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability allows any malicious unauthentic | Apr 29, 2025 | 6.1 | 28 | NO | YES |
CVE-2025-46550MEDIUM YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker can use a r | Apr 29, 2025 | 6.1 | 27 | NO | YES |
CVE-2025-46549MEDIUM YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having t | Apr 29, 2025 | 6.1 | 27 | NO | YES |
CVE-2025-46347CRITICAL YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used to write a file with a PHP extensi | Apr 29, 2025 | 9.8 | 26 | NO | NO |
CVE-2024-51478CRITICAL YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered an | Oct 31, 2024 | 9.1 | 25 | NO | NO |
CVE-2021-43091HIGH An SQL Injection vlnerability exits in Yeswiki doryphore 20211012 via the email parameter in the registration form. | Mar 25, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yeswiki.
Media articles that mention a CVE ID that affects a product developed by Yeswiki — matched by CVE ID, not by vendor name.