CVE-2026-104471
Deferred Deferred - Pending Action

YesWiki Unrestricted File Upload via Bazar CSV Import

Vulnerability report for CVE-2026-104471, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV import preview. Attackers can import a CSV whose file or image field references a remote .php URL, which is saved without extension checks and executed as server-side code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

YesWiki before version 4.6.7 has an unrestricted file upload vulnerability in the Bazar CSV import feature. Authenticated administrators can import a CSV file with a field referencing a remote PHP URL. The system saves this file without checking the extension, allowing the PHP code to be executed as server-side scripts in the web-accessible files/ directory.

Detection Guidance

Check YesWiki versions before 4.6.7 by running: grep -r 'YesWiki' /path/to/yeswiki/installation or check the version in the admin panel. Look for unexpected files in the web-accessible files/ directory, especially .php files not created by legitimate processes.

Impact Analysis

This vulnerability allows attackers with admin access to upload and execute arbitrary PHP code on the server. This can lead to full server compromise, data theft, or further network infiltration. The impact includes remote code execution, unauthorized file writes, and bypass of normal upload security checks.

Compliance Impact

This vulnerability can lead to data breaches, unauthorized access, and loss of sensitive data, which may violate GDPR, HIPAA, and other compliance standards. Organizations could face legal penalties, reputational damage, and loss of trust due to non-compliance resulting from this security flaw.

Mitigation Strategies

Upgrade YesWiki to version 4.6.7 or later immediately. If upgrading is not possible, restrict access to the Bazar CSV import feature and disable remote file downloads in CSV imports. Review files/ directory for unauthorized PHP files and remove them.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104471. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart