CVE-2026-104447 | YesWiki up to 4.6.6 Autoupdate UpdateAction package cross-site request forgery
A vulnerability, which was classified as problematic, has been found in YesWiki up to 4.6.6. Impacted is the function UpdateAction of the component Autoupdate. The manipulation of the argument package leads to cross-site request forgery.
This vulnerability is traded as CVE-2026-104447. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More