---
id: CVE-2026-104470
title: >-
  YesWiki before 4.6.7 contains a server-side request forgery vulnerability in
  the Bazar valeur action that allows page editors to make the server fetch
  arbitrary URLs
summary: >-
  YesWiki before 4.6.7 contains a server-side request forgery vulnerability in
  the Bazar valeur action that allows page editors to make the server fetch
  arbitrary URLs. Attackers can supply loopback or internal URLs in the url
  parameter to…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'
cwe:
  - CWE-79
vendor: YesWiki
product: yeswiki
affected:
  - yeswiki < 4.6.7
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T12:17:19.990'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104470'
references:
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-6rvf-7pwm-6j44'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-ssrf-and-xss-via-bazar-valeur-action
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T12:17:44.350Z'
---

## Overview

YesWiki before 4.6.7 contains a server-side request forgery vulnerability in the Bazar valeur action that allows page editors to make the server fetch arbitrary URLs. Attackers can supply loopback or internal URLs in the url parameter to probe internal services and inject unescaped remote HTML that executes scripts in viewers' browsers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
