Unauthenticated Server-Side Request Forgery in YesWiki Product by YesWiki
CVE-2026-104442

6.9MEDIUM

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104442?

YesWiki prior to version 4.6.7 is susceptible to an unauthenticated server-side request forgery (SSRF) vulnerability. By manipulating the syndication action through the render handler's content parameter, remote attackers can instruct the server to retrieve arbitrary URLs. This vulnerability poses significant risks as it can allow attackers to access internal hosts and ports, exfiltrate feed content, and lead to unauthorized file downloads within the server’s directory. Organizations using affected versions are recommended to upgrade to the latest version to mitigate potential exploitation.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

skeletonsec
.