CVE-2025-46347

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 29, 2025
Updated: May 9, 2025
CWE ID 116

Summary

CVE-2025-46347 is a remote code execution vulnerability affecting the YesWiki wiki system before version 4.5.4. An attacker can exploit this flaw by performing an arbitrary file write, creating a file with a PHP extension that can be executed when accessed through a web browser. This vulnerability can lead to a complete compromise of the server, potentially without the user's knowledge. The issue has been addressed in the latest version, 4.5.4.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share