CVE-2026-104451 UNKNOWN

CVE-2026-104451

Published: 2026-10-02

Description

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page revisions through GET requests lacking CSRF token validation. Attackers can lure write-capable users into a top-level navigation with the restoreRevisionId parameter, silently overwriting current page content with stale or vandalized revisions.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…