CVE WATCH / VULNERABILITY DETAIL
CVE-2026-104439
MEDIUMCVSS 5.3NVD feed
Published 2 October 2026 · tracked since 3 October 2026
Description
YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recovery page without rate limiting to identify valid a
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-104466 MEDIUM 5.4
- CVE-2026-104460 HIGH 7.5
- CVE-2026-104454 MEDIUM 5.3
- CVE-2026-104457 HIGH 8.6
- CVE-2026-104450 MEDIUM 6.5
- CVE-2026-104440 MEDIUM 5.3
- CVE-2026-104441 MEDIUM 5.3
- CVE-2026-104414 HIGH 8.1
- CVE-2026-96990
- CVE-2026-94651