CVE-2025-46347: YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution
An arbitrary file write can be used to write a file with a PHP extension, which then can be browsed to in order to execute arbitrary code on the server.
All testing was performed on a local docker setup running the latest version of the application.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-46347 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →