CVE-2025-46348: YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download
(updated )
The request to commence a site backup can be performed without authentication. Then these backups can also be downloaded without authentication.
The archives are created with a predictable filename, so a malicious user could create an archive and then download the archive without being authenticated.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-46348 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →