CVE-2026-104461
Deferred Deferred - Pending Action

Stored XSS in YesWiki via SVG File Upload

Vulnerability report for CVE-2026-104461, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extension and never calls HtmlPurifierService::cleanFile, so SVG files are stored verbatim and served inline as image/svg+xml. Authenticated users can submit entries via POST /api/entries/{formId} with SVG files containing script that executes in the wiki origin when the file is opened, enabling administrator session or account compromise.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in YesWiki versions before 4.6.7. It affects the Bazar FileField component where SVG files are uploaded without proper sanitization. The application only checks file extensions but does not clean the SVG content, allowing malicious scripts to execute when the file is opened.

Detection Guidance

To detect this vulnerability, inspect YesWiki installations for SVG files in the files/ directory, particularly those uploaded via the Bazar FileField. Check for files with .svg extensions that contain JavaScript payloads like <script> or onload events. Review server logs for POST requests to /api/entries/{formId} with SVG uploads.

Impact Analysis

An attacker could upload a malicious SVG file containing JavaScript. When the file is accessed, the script runs in the wiki's origin, potentially stealing sessions, enabling CSRF attacks, defacing the site, or escalating privileges to compromise administrator accounts.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. It may result in data breaches, non-compliance penalties, and loss of trust.

Mitigation Strategies

Immediately upgrade YesWiki to version 4.6.7 or later. Disable SVG uploads in the Bazar FileField if possible. Implement server-side SVG sanitization using tools like HtmlPurifierService::cleanFile. Add Content-Security-Policy headers to restrict inline script execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104461. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart