CVE-2026-104470
Executive Summary
YesWiki versions <4.6.7 are vulnerable to SSRF via the Bazar valeur action's url parameter. Page editors can embed the action with a champ parameter in wiki markup, causing the server to fetch arbitrary URLs, including loopback or internal services. The fetched content is partially rendered into the page, enabling attackers to read internal data. No current CISA KEV listing.
Authoritative CVE Metadata - CVSS Base Score: 5.0 (MEDIUM) - Published: 2026-10-02T12:17:19.870 - Last Modified: 2026-10-04T16:16:29.807
Original Description: YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows page editors to make the server fetch arbitrary URLs via the url parameter of the Bazar valeur action. Attackers can embed the action with a champ parameter in wiki markup to reach loopback or internal services and partially read responses rendered into the page.
"Kindness is the language which the deaf can hear and the blind can see."
— Mark Twain