CVE-2026-104470: YesWiki before 4.6.7 SSRF and XSS via Bazar valeur Action
YesWiki before 4.6.7 contains a server-side request forgery vulnerability in the Bazar valeur action that allows page editors to make the server fetch arbitrary URLs. Attackers can supply loopback or internal URLs in the url parameter to probe internal services and inject unescaped remote HTML that executes scripts in viewers' browsers.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs page-editor privileges in YesWiki. They can use the Bazar valeur action's url parameter to make the server request arbitrary URLs and to inject remote HTML that runs in viewers' browsers.
What systems or users are exposed by a successful exploit?
The YesWiki server may be used to probe loopback or internal services reachable from that server. Users viewing content containing injected remote HTML may have scripts executed in their browsers.
Which versions are affected?
YesWiki versions before 4.6.7 are affected.