Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication action through the render handler's content parameter. Attackers can target internal hosts and ports, read back fetched feed content in the rendered page, and cause feed enclosures to be downloaded into the files directory. | |
| Title | YesWiki before 4.6.7 Unauthenticated SSRF via syndication Action | |
| First Time appeared |
Yeswiki
Yeswiki yeswiki |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yeswiki
Yeswiki yeswiki |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T11:38:17.070Z
Reserved: 2026-10-02T00:53:03.851Z
Link: CVE-2026-104442
No data.
Status : Deferred
Published: 2026-10-02T12:17:15.153
Modified: 2026-10-02T12:17:15.273
Link: CVE-2026-104442
No data.
OpenCVE Enrichment
Updated: 2026-10-02T13:15:16Z
-
CWE-918
Server-Side Request Forgery (SSRF)