Blind Server-Side Request Forgery in YesWiki by YesWiki
CVE-2026-104440
6.9MEDIUM
What is CVE-2026-104440?
A vulnerability exists in YesWiki prior to version 4.6.7 that allows unauthenticated attackers to exploit a blind server-side request forgery (SSRF) via the 'idtypeannonce' parameter of the /api/entries/bazarlist endpoint. Due to the flawed implementation of the isValidURL() function, which always returns true, attackers can craft requests to probe internal networks and obtain sensitive internal services or metadata endpoints using curl in the loadURLContent() function.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
