Unauthenticated Server-Side Request Forgery in YesWiki by YesWiki
CVE-2026-104441

6.9MEDIUM

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104441?

YesWiki prior to version 4.6.7 is susceptible to an unauthenticated server-side request forgery vulnerability. This flaw enables remote attackers to manipulate the server into making requests to arbitrary hosts and ports via the {{valeur}} action's url parameter. By exploiting this vulnerability, attackers can submit crafted requests through the content parameter in handlers/page/render.php, potentially probing internal HTTP services and accessing response data that conforms to fiche markup.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

skeletonsec
.