PoC Index

CVE-2025-31131

HIGH 8.6EPSS 5.4%

YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability is fixed in 4.5.2.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS v3.1
8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS
5.38% chance of exploitation in the next 30 days, 92th percentile
Nuclei
high · CWE-22
Published
2025-04-01

Proof-of-concept exploits (3)

Nuclei templates (1)

ExploitDB entries (1)

References

Related