HIGH 7.1 NVD
CVE-2026-104439
YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addre
YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recovery page without rate limiting to identify valid accounts for targeted phishing or password-spraying.
References
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-892r-45m6-45xc
- https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-user-enumeration-via-lost-passwo
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-892r-45m6-45xc
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-10-02 via NVD.
vulnfeed aggregates 10476 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.