Medium severity5.4NVD Advisory· Published Oct 2, 2026· Updated Oct 2, 2026
CVE-2026-104461
CVE-2026-104461
Description
YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extension and never calls HtmlPurifierService::cleanFile, so SVG files are stored verbatim and served inline as image/svg+xml. Authenticated users can submit entries via POST /api/entries/{formId} with SVG files containing script that executes in the wiki origin when the file is opened, enabling administrator session or account compromise.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.