YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability is fixed in 4.5.2.
CVE ID: CVE-2025-31131
CVSS Base Severity: HIGH
CVSS Base Score: 8.6
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vendor: YesWiki
Product: yeswiki
http/cves/2025/CVE-2025-31131.yaml
EPSS Score: 26.41% (probability of being exploited)
EPSS Percentile: 95.98% (scored less or equal to compared to others)
EPSS Date: 2025-04-30 (when was this score calculated)