CVE-2026-104452: YesWiki before 4.6.7 CSRF Attachment Deletion via filemanager Handler
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the filemanager page handler, which deletes page attachments on GET requests without validating a CSRF token. Attackers can lure a logged-in page owner or administrator into a top-level GET navigation with do=del, erase, or emptytrash, deleting or permanently purging the page's attachments.
Affected Software
Event History
Frequently Asked Questions
Who can be targeted by this issue?
A logged-in page owner or administrator can be targeted because the vulnerable handler performs attachment deletion using that user’s session. An attacker does not need authentication, but must persuade the victim to follow a top-level GET navigation.
What actions can an attacker trigger?
The vulnerable filemanager handler accepts do=del, erase, or emptytrash through GET requests. Depending on the action, this can delete page attachments or permanently purge them.
Which versions are affected?
YesWiki versions before 4.6.7 are affected. Updating to 4.6.7 or later addresses the stated affected-version range.