Authorization Flaw in YesWiki Affects User Content Integrity
CVE-2026-104450

8.2HIGH

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104450?

YesWiki prior to version 4.6.7 suffers from a significant vulnerability where unauthenticated users can bypass access control lists (ACLs). This flaw exists in the pointimage action, allowing attackers to post page tags, titles, and descriptions to any page that renders the {{pointimage}} tag. As a result, attackers are able to inject raw HTML or JavaScript into wiki pages, leading to stored cross-site scripting (XSS) vulnerabilities that threaten both viewers' and administrators' web browsers.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.