Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extension and never calls HtmlPurifierService::cleanFile, so SVG files are stored verbatim and served inline as image/svg+xml. Authenticated users can submit entries via POST /api/entries/{formId} with SVG files containing script that executes in the wiki origin when the file is opened, enabling administrator session or account compromise. | |
| Title | YesWiki before 4.6.7 Stored XSS via Unsanitized SVG Upload in Bazar FileField | |
| First Time appeared |
Yeswiki
Yeswiki yeswiki |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yeswiki
Yeswiki yeswiki |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T11:38:29.623Z
Reserved: 2026-10-02T00:55:11.982Z
Link: CVE-2026-104461
No data.
Status : Deferred
Published: 2026-10-02T12:17:18.303
Modified: 2026-10-02T12:17:18.423
Link: CVE-2026-104461
No data.
OpenCVE Enrichment
Updated: 2026-10-02T16:45:17Z