CVE-2025-46349

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Apr 29, 2025
Updated: May 9, 2025
CWE ID 79

Summary

CVE-2025-46349 is a reflected XSS vulnerability affecting YesWiki, an open-source wiki system written in PHP. Prior to version 4.5.4, the file upload form in YesWiki was susceptible to this issue. Malicious users could exploit this vulnerability by creating a specially crafted link. Upon clicking the link, victims would inadvertently execute arbitrary code, potentially leading to data theft or unauthorized system access. This issue has been addressed and resolved in the updated version 4.5.4.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share