CVE-2025-52277: XSS
Cross Site Scripting vulnerability in YesWiki v.4.5.4 allows a remote attacker to execute arbitrary code via a crafted payload to the meta configuration robots field.
Other sources
Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted payload to the meta configuration robots field
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52277?
CVE-2025-52277 is a high severity Cross Site Scripting vulnerability that allows remote attackers to execute arbitrary code.
How do I fix CVE-2025-52277?
To mitigate CVE-2025-52277, update YesWiki to version 4.5.5 or later where the vulnerability has been resolved.
Which versions of YesWiki are affected by CVE-2025-52277?
CVE-2025-52277 affects YesWiki versions up to and including 4.5.4.
How does CVE-2025-52277 impact YesWiki installations?
CVE-2025-52277 allows an attacker to execute arbitrary code through a crafted payload in the meta configuration robots field.
What types of attacks can be executed through CVE-2025-52277?
CVE-2025-52277 can be exploited for Cross Site Scripting attacks, enabling attackers to potentially steal user data or perform actions on behalf of users.