CVE-2026-104451: YesWiki before 4.6.7 CSRF Page Revision Restore via RevisionsHandler
Published Oct 2, 2026
·Updated
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page revisions through GET requests lacking CSRF token validation. Attackers can lure write-capable users into a top-level navigation with the restoreRevisionId parameter, silently overwriting current page content with stale or vandalized revisions.
Affected Software
1 affected component
YesWiki YesWiki<4.6.7
Event History
Oct 2, 2026
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need, and who must they target?
The attacker does not need privileges, but successful exploitation requires luring a user with write capability into navigating to the crafted request. The affected user’s permissions enable the revision restoration.
2
Which deployments are identified as affected?
YesWiki versions before 4.6.7 are identified as affected.