Medium severity5.4NVD Advisory· Published Oct 2, 2026· Updated Oct 2, 2026
CVE-2026-104466
CVE-2026-104466
Description
YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or post comments to inject event handlers by placing quotes in markdown image URLs. Attackers can store a crafted markdown image whose src breaks out of the attribute to add an onerror handler, executing JavaScript in viewers' browsers, including administrators.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.