Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or post comments to inject event handlers by placing quotes in markdown image URLs. Attackers can store a crafted markdown image whose src breaks out of the attribute to add an onerror handler, executing JavaScript in viewers' browsers, including administrators. | |
| Title | YesWiki before 4.6.7 Stored XSS via Wakka Markdown Image src Attribute | |
| First Time appeared |
Yeswiki
Yeswiki yeswiki |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yeswiki
Yeswiki yeswiki |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T11:38:32.854Z
Reserved: 2026-10-02T00:55:11.982Z
Link: CVE-2026-104466
No data.
Status : Deferred
Published: 2026-10-02T12:17:19.217
Modified: 2026-10-02T12:17:19.333
Link: CVE-2026-104466
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')