HIGHCVSS 7.1
YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a victim tag, bypassing per-page write ACLs to replace content and reparent existing pages or comments.
Published 2026-10-02 · last modified 2026-10-02
← Get alerted the moment a CVE hits your gear — subscribe freeNcerio by BeyondNets · data from NVD, CISA KEV, EPSS.