Server-Side Request Forgery in YesWiki Affects Page Editors
CVE-2026-104470

5.3MEDIUM

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104470?

YesWiki, prior to version 4.6.7, is susceptible to a server-side request forgery vulnerability found in the Bazar valeur action. This allows an attacker to manipulate the server's ability to retrieve arbitrary internal URLs. By exploiting this vulnerability, unauthorized individuals can probe back-end services and inject unescaped HTML scripts that may execute in the browsers of users viewing the affected pages. This can lead to further security incidents, as sensitive internal information could be exposed.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sondt99
.