CVE-2026-104455
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Oct 02, 2026
Vendor
unknown
Description
YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content via the recentchangesrssplus RSS action. Attackers can request the xml method of a page hosting the action to retrieve 500-character body excerpts of every latest page, including read-restricted drafts and notes.