CVE-2026-104466
Deferred Deferred - Pending Action

Stored XSS in YesWiki via Markdown Image URLs

Vulnerability report for CVE-2026-104466, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or post comments to inject event handlers by placing quotes in markdown image URLs. Attackers can store a crafted markdown image whose src breaks out of the attribute to add an onerror handler, executing JavaScript in viewers' browsers, including administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

YesWiki before version 4.6.7 has a stored cross-site scripting (XSS) vulnerability in the Wakka markdown image formatter. Attackers with edit or comment privileges can inject malicious event handlers, such as onerror, by crafting markdown image URLs with quotes. This breaks out of the src attribute and executes JavaScript when the image fails to load or when users view the page.

Detection Guidance

To detect this vulnerability, inspect YesWiki instances for markdown image tags with malformed src attributes containing quotes or event handlers like onerror. Check page edits or comments for payloads such as ![](x" onerror=alert(1)). Review YesWiki versions prior to 4.6.7 for the Wakka formatter in formatters/wakka.php.

Impact Analysis

This vulnerability allows attackers to execute arbitrary JavaScript in the browsers of users viewing the compromised page, including administrators. Potential impacts include unauthorized content modification, data theft, session hijacking, or further attacks against users. The attack requires some user interaction and privileges but can have significant consequences.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by enabling unauthorized access to user data, potential data breaches, or loss of data integrity. Organizations using affected YesWiki versions may face legal penalties, reputational damage, and failure to meet regulatory requirements for data protection and security.

Mitigation Strategies

Upgrade YesWiki to version 4.6.7 or later immediately. If upgrading is not possible, disable markdown image rendering in the Wakka formatter or restrict user permissions to prevent untrusted users from editing pages or posting comments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104466. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart