CVE-2026-104461: YesWiki before 4.6.7 Stored XSS via Unsanitized SVG Upload in Bazar FileField

Published Oct 2, 2026
·
Updated

YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extension and never calls HtmlPurifierService::cleanFile, so SVG files are stored verbatim and served inline as image/svg+xml. Authenticated users can submit entries via POST /api/entries/{formId} with SVG files containing script that executes in the wiki origin when the file is opened, enabling administrator session or account compromise.

Affected Software

1 affected component
YesWiki YesWiki<4.6.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade YesWiki to a version that resolves this vulnerability.

    Fixed in 4.6.7

Event History

Oct 2, 2026
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user who can submit a Bazar entry through the affected API endpoint can upload a crafted SVG file. Exploitation also requires someone to open the uploaded SVG in the YesWiki origin.

2

What is the likely impact if an administrator opens a malicious SVG?

Script embedded in the SVG can execute in the wiki origin. This can enable compromise of an administrator's session or account, and the stated impact includes low confidentiality and integrity effects across a changed scope.

3

Are SVG uploads protected by content sanitization in affected versions?

No. The affected Bazar FileField validates only the file extension and does not call HtmlPurifierService::cleanFile, so SVG content is stored verbatim and served inline as image/svg+xml.

4

How can I determine whether my deployment is affected?

Deployments running YesWiki before 4.6.7 are affected. You can also verify exposure by checking whether Bazar FileField accepts SVG uploads and stores them without invoking HtmlPurifierService::cleanFile.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203