Unrestricted File Upload Flaw in YesWiki by YesWiki
CVE-2026-104471
8.6HIGH
What is CVE-2026-104471?
YesWiki versions prior to 4.6.7 are susceptible to an unrestricted file upload vulnerability, which allows authenticated administrators to upload malicious files through the Bazar CSV import preview feature. An attacker can exploit this flaw by crafting a CSV file that points to a remote .php URL in its file or image field. As a result, the application saves this input without proper extension validation, resulting in the execution of server-side code on the web server. This flaw poses significant security risks as it could potentially lead to unauthorized access to the application and unauthorized actions on behalf of admins.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
