CVE-2026-104465: YesWiki before 4.6.7 Reflected XSS via field Parameter in mail Handler
YesWiki before 4.6.7 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the field parameter of the mail handler. Attackers can craft links whose field value breaks out of the ajax-mail-form action attribute to execute JavaScript in victims' browsers.
Affected Software
Event History
Frequently Asked Questions
Which YesWiki versions are affected?
YesWiki versions before 4.6.7 are affected. Upgrading to 4.6.7 or later removes the affected version range identified in the advisory.
What must an attacker do to exploit this issue?
An unauthenticated attacker must craft a link containing a malicious field parameter and convince a victim to open it. The payload executes in the victim's browser after the parameter breaks out of the ajax-mail-form action attribute.
Are unauthenticated users exposed?
Yes. Exploitation does not require attacker authentication, but it does require victim interaction with a crafted link.