PT-2026-104643 · Yeswiki · Yeswiki

·

CVE-2026-105224

·

Published

2026-10-04

·

Updated

2026-10-04

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions YesWiki versions prior to 4.6.7
Description A cross-site scripting issue exists in the Bazar valeur action. Page editors can inject scripts by rendering unescaped HTML fetched from a remote URL. An attacker can direct the 'tools/bazar/actions/valeur.php' endpoint to a controlled server that returns BAZ fiche titre markup containing an img onerror handler, which executes the script in the browser of any user viewing the page.
Recommendations Update YesWiki to version 4.6.7 or later. As a temporary mitigation, restrict access to the 'tools/bazar/actions/valeur.php' endpoint.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105224
GHSA-6RVF-7PWM-6J44

Affected Products

Yeswiki