github.com
https://github.com/YesWiki/yeswiki CVE-2026-34598
HIGH
YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter"
Record summary
CVE-2026-34598 has a selected CVSS score of 7.1 (high).
Description
YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form title field. A malicious attacker can inject JavaScript without any authentication via a form title that is saved in the backend database. When any user visits that injected page, the JavaScript payload gets executed. This issue has been patched in version 4.6.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
yeswikiBrowse YesWiki / yeswiki | CVE List | < 4.6.0 | affected |
yeswiki/yeswikiBrowse Packagist / yeswiki/yeswiki | GitHub Advisory | Before 4.6.0 · Fixed in 4.6.0 | affected |
References
4github.com
https://github.com/YesWiki/yeswiki/releases/tag/v4.6.0 github.comConfirmation
https://github.com/YesWiki/yeswiki/security/advisories/GHSA-37fq-47qj-6j5j nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-34598