🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-104469 YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerat... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104468 YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104467 YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104466 YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or post comment... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104465 YesWiki before 4.6.7 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the field par... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104464 YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by su... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104463 YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104462 YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104461 YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extensio... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104460 YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104459 YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService that allows unauthenticated attackers to trigger HTTPS r... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104458 YesWiki before 4.6.7 contains a server-side request forgery vulnerability in validateKeyIdUrl() that allows unauthenticated attackers to bypass the SS... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104457 YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104456 YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is concatenated ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104455 YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content via the rec... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104454 YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an O(n^2) markdown-link regex. Unauthentic... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104453 YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action that allows attackers to delete tag associations by lu... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104452 YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the filemanager page handler, which deletes page attachments on GET reques... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104451 YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page revisions throu... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104450 YesWiki before 4.6.7 contains a missing authorization flaw in the pointimage action (tools/attach/actions/pointimage.php), which saves content to an a... | HIGH | ????? | ????? | NVD | 5 days ago |