Cross-Site Scripting Vulnerability in YesWiki Product
CVE-2026-105224

5.1MEDIUM

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105224?

YesWiki versions prior to 4.6.7 are susceptible to a Cross-Site Scripting (XSS) vulnerability that impacts the Bazar valeur action. This flaw allows page editors to inject malicious scripts by rendering unescaped HTML from a remote URL. By exploiting this vulnerability, attackers can manipulate requests to tools/bazar/actions/valeur.php, directing it to a controlled server. If the server responds with specially crafted BAZ_fiche_titre markup including an onerror handler within an image tag, the injected script can execute in the web browsers of all users who view the affected pages.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sondt99
.