peter bassill · operator
$ cve CVE-2025-31131 JSON

CVE-2025-31131 EXPLOIT

8.6
HIGH · CVSS 3.1 · EPSS 5.5% (pctl 93)

Patch early

A public exploit exists.

Description

YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability is fixed in 4.5.2.

Scoring

CVSS8.6 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS5.47% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2025-04-01
Last modified2026-06-17

Affected (1)

VendorProduct
yeswikiyeswiki

Public exploits

SourceTitleDate
exploit-dbYesWiki 4.5.1 - Unauthenticated Path Traversal2025-04-07

References

→ the Explorer  ·  watch your stack  ·  NVD