Authorization Flaw in YesWiki Affects User Content Integrity
CVE-2026-104450
8.2HIGH
What is CVE-2026-104450?
YesWiki prior to version 4.6.7 suffers from a significant vulnerability where unauthenticated users can bypass access control lists (ACLs). This flaw exists in the pointimage action, allowing attackers to post page tags, titles, and descriptions to any page that renders the {{pointimage}} tag. As a result, attackers are able to inject raw HTML or JavaScript into wiki pages, leading to stored cross-site scripting (XSS) vulnerabilities that threaten both viewers' and administrators' web browsers.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
