CVE-2026-105224
Deferred Deferred - Pending Action

Cross-Site Scripting in YesWiki via Bazar valeur Action

Vulnerability report for CVE-2026-105224, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by rendering unescaped HTML fetched from a remote URL. Attackers can point tools/bazar/actions/valeur.php at a controlled server returning BAZ_fiche_titre markup with an img onerror handler, executing script in every viewer's browser.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)
yeswiki yeswiki to 4.6.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in YesWiki versions before 4.6.7. It exists in the Bazar valeur action where page editors can inject malicious scripts by fetching unescaped HTML from a remote URL. Attackers can craft a URL pointing to a controlled server returning BAZ_fiche_titre markup with an img tag containing an onerror handler. When rendered, this executes arbitrary JavaScript in the browsers of all users viewing the affected page.

Detection Guidance

Check YesWiki versions before 4.6.7 by running: grep -r 'YesWiki' /path/to/yeswiki/installation or check the version in the admin panel. Inspect Bazar valeur action usage in pages for external URL references. Look for img tags with onerror handlers in rendered pages. Monitor network traffic for unexpected outbound requests from tools/bazar/actions/valeur.php.

Impact Analysis

If you are a user viewing a page with this vulnerability, an attacker could execute arbitrary JavaScript in your browser. This could lead to session hijacking, theft of sensitive data like cookies or credentials, or defacement of the page. The impact requires an attacker to have page-editing privileges to inject the malicious payload.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. It may result in data breaches, unauthorized data disclosure, or integrity violations, potentially leading to regulatory penalties and loss of trust.

Mitigation Strategies

Upgrade YesWiki to version 4.6.7 or later immediately. If upgrading is not possible, disable the Bazar valeur action by removing or restricting access to tools/bazar/actions/valeur.php. Implement input validation for URLs in the Bazar module. Use HtmlPurifierService to sanitize all HTML output. Restrict page editor privileges to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105224. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart