S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 12, 2026

CVE-2025-46349 Scanner

CVE-2025-46349 Scanner - Cross-Site Scripting (XSS) vulnerability in YesWiki

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-46349
6.1
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability allows any malicious unauthenticated user to create a link that can be clicked on by the victim to perform arbitrary actions. This issue has been patched in version 4.5.4.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
yeswikiby YesWiki
< 4.5.4
Updated Aug 22, 2026View on NVD →
Detail

YesWiki is an open-source wiki system that is used for creating collaborative content environments. It is primarily utilized by organizations, teams, and educators to facilitate content sharing and collaborative workspaces. YesWiki allows users to create, edit, and manage content in a structured format while supporting various multimedia content forms. It is easy to install and extend, making it a popular choice for small to medium-sized collaborative projects. The platform is known for its simplicity and support of community-driven plugin enhancements, allowing adaptability for various use cases. Its capabilities include document management, group collaboration, and streamlined sharing of information.

Cross-Site Scripting (XSS) is a type of vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. This vulnerability typically occurs when an application fails to validate or escape user input before incorporating it into the webpage's content. In the context of YesWiki, this reflected XSS vulnerability is linked to the file upload form, where malicious scripts can be executed. If a user clicks on a crafted link, it can lead to the execution of code that can compromise visitor interactions. XSS vulnerabilities are critical in that they can facilitate unauthorized actions in sessions initiated by unwary users.

The specific vulnerability involves the ability to upload a file or form input that includes a malicious script. The script can be triggered when a user visits a particular crafted URL, leading to execution within the context of the vulnerable website. The vulnerability involves the endpoint handling file uploads and does not sufficiently sanitize input data. The reflected script used in this vulnerability executes within the Upload form context, as confirmed by testing with crafted payloads. This vulnerability requires user interaction, specifically a click on the malicious URL, affirming the XSS nature.

When exploited, this vulnerability can allow attackers to perform actions on behalf of an authenticated user, such as stealing session cookies, redirecting to phishing sites, or modifying the content displayed to the user. In some cases, it may lead to further compromise of user accounts or unauthorized actions being executed. Those actions would result in loss of user account confidentiality and integrity on the YesWiki installation, leading to trust erosion in affected websites. Furthermore, compromised installations could serve as a pivot point for further attacks within network environments.

REFERENCES

Solution Advice
  • Update YesWiki to version 4.5.4 or later, where this vulnerability is patched.
  • Implement input validation and escaping strategies for any user input content.
  • Use Content Security Policy (CSP) headers to reduce the risk of external script execution.
  • Regularly audit and review code changes for security implications related to user inputs.
  • Educate users about the risks of clicking on unverified links to avoid XSS attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.