Stored Cross-Site Scripting Vulnerability in YesWiki by YesWiki
CVE-2026-104466

5.1MEDIUM

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104466?

YesWiki prior to version 4.6.7 is susceptible to a stored cross-site scripting vulnerability found in the formatters/wakka.php file. This flaw permits users with page editing or commenting privileges to inject malicious event handlers through specially crafted markdown image URLs. By manipulating the src attribute, attackers can cause JavaScript execution in the browsers of viewers, including administrators, thereby posing significant risks to site security.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sondt99
.