{"id":"CVE-2026-104471","title":"YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV import preview","summary":"YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV import preview. Attackers can import a CSV whose file o…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-434"],"vendor":"YesWiki","product":"yeswiki","affected":["yeswiki < 4.6.7"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T14:17:09.137","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104471","references":[{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-v3gq-c7c6-mxw3","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-unrestricted-file-upload-via-bazar-csv-import","label":"disclosure@vulncheck.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-v3gq-c7c6-mxw3","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-10-02T13:42:51.998929Z"},"ingestedAt":"2026-10-02T12:17:44.350Z","slug":"CVE-2026-104471","body":"## Overview\n\nYesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV import preview. Attackers can import a CSV whose file or image field references a remote .php URL, which is saved without extension checks and executed as server-side code.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":39.6,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":214939,"id":"CVE-2026-104471","ts":1790950876072,"field":"exploit_available","old":"false","new":"true"}]}