PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Web Vulnerabilities·Updated Jan 12, 2026

YesWiki < 4.5.4 - Cross-Site Scripting

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-46550
4.3
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability may also allow attackers to deface the website or embed malicious content. This issue has been patched in version 4.5.4.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
yeswikiby YesWiki
< 4.5.4
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

YesWiki < 4.5.4 - Cross-Site Scripting CVE-2025-46550 Scanner | S4E