CVE-2026-104453
Deferred Deferred - Pending Action

Cross-Site Request Forgery in YesWiki Leading to Tag Deletion

Vulnerability report for CVE-2026-104453, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action that allows attackers to delete tag associations by luring administrators to crafted GET links. Attackers can supply a wide id range in the delete_tag parameter via top-level navigation, carrying the SameSite=Lax admin cookie, to bulk-delete tag triples.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104453 is a Cross-Site Request Forgery (CSRF) vulnerability in YesWiki versions before 4.6.7. It exists in the admintag action, allowing attackers to delete tag associations by tricking administrators into clicking malicious GET links. The vulnerability stems from missing CSRF protection in admintag.php, which only checks admin privileges but not tokens. Since admin cookies use SameSite=Lax, external GET requests still include the cookie, enabling unauthorized deletions.

Detection Guidance

Check YesWiki version with: grep -r 'YesWiki' /path/to/yeswiki/version.php. If version is 4.6.6 or earlier, the system is vulnerable. Look for unusual tag deletions in logs or database queries involving the admintag action.

Impact Analysis

An attacker could exploit this to delete tag associations in bulk, disrupting navigation and tagging functionality on the YesWiki site. While the site remains operational, loss of tag metadata may affect organization and accessibility of content. Administrators may need to restore deleted tags manually.

Compliance Impact

This CSRF vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized modifications to tag associations, which may affect data integrity and access controls. Unauthorized deletions of tag metadata could compromise how data is organized, tracked, or secured, depending on how tags are used in the system. However, the vulnerability does not directly expose sensitive data but may disrupt organizational workflows that rely on proper tagging for compliance documentation.

Mitigation Strategies

Upgrade YesWiki to version 4.6.7 or later immediately. Ensure POST requests are enforced for admintag actions and CSRF tokens are validated before deletions. Review and restore any deleted tag associations from backups.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104453. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart