Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
YesWiki versions prior to 4.6.7 have a server-side request forgery (SSRF) vulnerability in the Bazar valeur action. This flaw allows page editors to cause the server to fetch arbitrary URLs, including internal or loopback addresses. Exploitation can lead to probing of internal services and injection of unescaped remote HTML, which may execute scripts in the browsers of users viewing the affected pages. The vulnerability has a CVSS 3.1 score of 7.4, indicating a medium severity level. Join the discussion | GCVE Database | 10/02/2026, 12:31:17 UTC Added: 10/02/2026, 17:48:58 UTC |
YesWiki versions prior to 4.6.7 have an authorization bypass vulnerability in the ApiService::isAuthorized() function. This flaw allows unauthenticated attackers to access admin-only API routes when public API mode is enabled. Exploitation can lead to unauthorized configuration changes and manipulation of backup archives, including listing, downloading, or deleting them. Join the discussion | GCVE Database | 10/02/2026, 12:31:17 UTC Added: 10/02/2026, 17:48:58 UTC |
YesWiki versions before 4.6.7 have a vulnerability where password reset tokens do not expire, allowing attackers to reuse old reset links. This flaw enables attackers who obtain unused reset URLs from various sources to reset passwords and take over accounts. The vulnerability is identified as CVE-2026-104468 and has a medium severity rating with a CVSS score of 4.8. Join the discussion | GCVE Database | 10/02/2026, 12:31:17 UTC Added: 10/02/2026, 17:48:58 UTC |
YesWiki versions prior to 4.5.3 contain multiple reflected cross-site scripting (XSS) vulnerabilities. These flaws allow remote attackers to inject malicious JavaScript code via unsanitized parameters such as incomingurl, id, file, tags, and template. Exploitation can occur when users, authenticated or not, open crafted links, potentially leading to session hijacking and unauthorized authenticated requests. The vulnerabilities have a medium severity rating with a CVSS score of 6.1. Join the discussion | GCVE Database | 10/02/2026, 12:31:17 UTC Added: 10/02/2026, 17:48:58 UTC |
YesWiki versions prior to 4.6.7 have a server-side request forgery (SSRF) vulnerability. This flaw allows unauthenticated attackers to send signed Follow activities to a public actor inbox route, causing the server to make unauthorized internal requests. Attackers can use their own keyId to sign these requests while specifying internal actor URLs, potentially accessing internal hosts or cloud metadata services. The vulnerability has a high severity rating with a CVSS score of 7. No explicit patch information is provided in the input data. Join the discussion | GCVE Database | 10/02/2026, 12:31:17 UTC Added: 10/02/2026, 17:48:58 UTC |
YesWiki versions before 4.6.7 have a session fixation vulnerability where the login process does not regenerate the PHP session ID. This flaw allows attackers who can set or obtain a victim's pre-authentication session cookie to hijack the victim's authenticated session and access private content with their privileges. Join the discussion | GCVE Database | 10/02/2026, 12:31:17 UTC Added: 10/02/2026, 17:48:56 UTC |
YesWiki versions before 4.6.7 have an unrestricted file upload vulnerability that allows authenticated administrators to upload and execute remote PHP files via the CSV import preview feature. This occurs because the application does not properly validate file extensions when importing CSV files referencing remote .php URLs, leading to server-side code execution. Join the discussion | GCVE Database | 10/02/2026, 12:31:17 UTC Added: 10/02/2026, 17:48:56 UTC |
YesWiki versions prior to 4.6.7 contain a server-side request forgery (SSRF) vulnerability. This flaw allows unauthenticated attackers to make server-side GET requests by providing an unvalidated actor URL to the Bazar abonnements sync action. Exploitation can target internal hosts or cloud metadata endpoints, with attacker-controlled outbox links enabling response data to be stored as readable Bazar entries. The vulnerability has a high severity rating with a CVSS score of 8.6. Join the discussion | GCVE Database | 10/02/2026, 12:31:17 UTC Added: 10/02/2026, 17:48:56 UTC |
YesWiki versions before 4.6.7 contain a stored cross-site scripting (XSS) vulnerability in the formatters/wakka.php component. This flaw allows users with permissions to edit pages or post comments to inject malicious event handlers via crafted markdown image URLs. The vulnerability enables attackers to execute arbitrary JavaScript in the browsers of users who view the affected pages, including administrators. Join the discussion | GCVE Database | 10/02/2026, 12:31:17 UTC Added: 10/02/2026, 17:48:56 UTC |
YesWiki versions before 4.6.7 have a reflected cross-site scripting (XSS) vulnerability in the mail handler's field parameter. This flaw allows unauthenticated attackers to inject malicious scripts by crafting links that manipulate the ajax-mail-form action attribute, potentially executing JavaScript in the browsers of users who click these links. Join the discussion | GCVE Database | 10/02/2026, 12:31:17 UTC Added: 10/02/2026, 17:48:56 UTC |
Showing 1 to 10 of 36 results