CVE WATCH / VULNERABILITY DETAIL
CVE-2026-104469
MEDIUMCVSS 6.8NVD feed
Published 2 October 2026 · tracked since 3 October 2026
Description
YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private con
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-103622 HIGH 8.8
- CVE-2026-103625 HIGH 8.8
- CVE-2026-90970 CRITICAL 9.9
- CVE-2026-39600 MEDIUM 4.7
- CVE-2026-104638 MEDIUM 5.3
- CVE-2026-104625 MEDIUM 6.3
- CVE-2026-104637 HIGH 7.3
- CVE-2026-93875 HIGH 7.2
- CVE-2026-19652 CRITICAL 9.8
- CVE-2026-104613 MEDIUM 6.3