Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| References |
|
Sun, 04 Oct 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YesWiki before 4.6.7 contains a server-side request forgery vulnerability in the Bazar valeur action that allows page editors to make the server fetch arbitrary URLs. Attackers can supply loopback or internal URLs in the url parameter to probe internal services and inject unescaped remote HTML that executes scripts in viewers' browsers. | YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows page editors to make the server fetch arbitrary URLs via the url parameter of the Bazar valeur action. Attackers can embed the action with a champ parameter in wiki markup to reach loopback or internal services and partially read responses rendered into the page. |
| Title | YesWiki before 4.6.7 SSRF and XSS via Bazar valeur Action | YesWiki before 4.6.7 SSRF via Bazar valeur Action url Parameter |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 02 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YesWiki before 4.6.7 contains a server-side request forgery vulnerability in the Bazar valeur action that allows page editors to make the server fetch arbitrary URLs. Attackers can supply loopback or internal URLs in the url parameter to probe internal services and inject unescaped remote HTML that executes scripts in viewers' browsers. | |
| Title | YesWiki before 4.6.7 SSRF and XSS via Bazar valeur Action | |
| First Time appeared |
Yeswiki
Yeswiki yeswiki |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yeswiki
Yeswiki yeswiki |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T14:59:42.904Z
Reserved: 2026-10-02T00:55:58.387Z
Link: CVE-2026-104470
Updated: 2026-10-02T15:19:42.670Z
Status : Deferred
Published: 2026-10-02T12:17:19.870
Modified: 2026-10-04T16:16:29.807
Link: CVE-2026-104470
No data.
OpenCVE Enrichment
Updated: 2026-10-04T17:30:16Z