Description
YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary hosts and ports via the {{valeur}} action's url parameter. Attackers can submit the action through the content parameter of handlers/page/render.php to probe internal HTTP services and read back response content matching fiche markup.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated SSRF allowing internal resource discovery
Action: Immediate Patch
AI Analysis

Impact

YesWiki installations running a version earlier than 4.6.7 are vulnerable to an unauthenticated server‑side request forgery (SSRF) via the {{valeur}} action. By including a crafted content value that references an arbitrary URL, a remote attacker can cause the YesWiki server to fetch data from any host and port reachable from the server. The application returns the fetched data in fiche markup, allowing the attacker to read the response body. This flaw permits disclosure of internal services and can serve as a foothold for further exploitation such as remote code execution.

Affected Systems

All installations of YesWiki with a version before 4.6.7 are affected. The issue is present in every deployment where the {{valeur}} tag is enabled, including community and private instances. Versions 4.6.7 and newer contain the necessary fix.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity risk. The exploit requires no authentication and can be triggered by any unauthenticated client that can reach the web application. Failure to mitigate can expose internal network traffic and data. Although no EPSS value is published and the vulnerability is not listed in the CISA KEV catalog, the nature of the flaw—unauthenticated SSRF—represents a common attack vector that can be leveraged in broader intrusion campaigns.

Generated by OpenCVE AI on October 2, 2026 at 12:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the YesWiki upgrade to version 4.6.7 or later to remediate the SSRF flaw.
  • If an upgrade cannot be performed immediately, configure the web server or application to block or disable the handlers/page/render.php endpoint that exposes the {{valeur}} action.
  • Use a web application firewall or outbound request filtering to block or restrict arbitrary external requests initiated by the application and monitor for anomalous outbound traffic.

Generated by OpenCVE AI on October 2, 2026 at 12:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary hosts and ports via the {{valeur}} action's url parameter. Attackers can submit the action through the content parameter of handlers/page/render.php to probe internal HTTP services and read back response content matching fiche markup.
Title YesWiki before 4.6.7 Unauthenticated SSRF via valeur Action
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-918
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:16.415Z

Reserved: 2026-10-02T00:53:03.851Z

Link: CVE-2026-104441

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:14.997

Modified: 2026-10-02T12:17:15.110

Link: CVE-2026-104441

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:00:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)