Cross-Site Scripting Vulnerability in YesWiki Product
CVE-2026-105224
5.1MEDIUM
What is CVE-2026-105224?
YesWiki versions prior to 4.6.7 are susceptible to a Cross-Site Scripting (XSS) vulnerability that impacts the Bazar valeur action. This flaw allows page editors to inject malicious scripts by rendering unescaped HTML from a remote URL. By exploiting this vulnerability, attackers can manipulate requests to tools/bazar/actions/valeur.php, directing it to a controlled server. If the server responds with specially crafted BAZ_fiche_titre markup including an onerror handler within an image tag, the injected script can execute in the web browsers of all users who view the affected pages.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
