Description
YesWiki before 4.6.7 contains a missing authorization flaw in the pointimage action (tools/attach/actions/pointimage.php), which saves content to an attacker-chosen page with write ACL checks bypassed. Unauthenticated attackers can POST pagetag, title, and description fields to any page rendering {{pointimage}} to append raw HTML or JavaScript to any wiki page, including pages whose write ACL restricts editing, causing stored cross-site scripting in viewers' and administrators' browsers.
Published: 2026-10-02
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross-Site Scripting (ACL bypass)
Action: Patch Immediately
AI Analysis

Impact

The flaw resides in the pointimage action of YesWiki versions earlier than 4.6.7. It is a missing authorization bug that allows anyone to POST content to any page that displays the {{pointimage}} macro, bypassing write ACL checks. Because the content is stored directly as raw HTML or JavaScript, the attacker can insert malicious code that will run in the browsers of every viewer, including administrators, when the page is rendered. The vulnerability is a Stored Cross‑Site Scripting flaw, which can lead to session hijacking, defacement, or arbitrary script execution. This is aligned with the Common Weakness Enumeration CWE‑79.

Affected Systems

YesWiki software from all releases before version 4.6.7 is affected. This includes all public deployments running YesWiki 4.6.0 through 4.6.6 and earlier. The issue is specific to the pointimage action located in tools/attach/actions/pointimage.php.

Risk and Exploitability

With a CVSS score of 8.2, this vulnerability is classified as High severity. The exploit requires only unauthenticated HTTP POST requests, meaning any attacker can trigger it without credentials. EPSS data is not available, but the lack of authentication prerequisites and the ability to affect all browsing users indicate a substantial likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but its high severity and broad impact warrant immediate attention.

Generated by OpenCVE AI on October 2, 2026 at 12:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YesWiki to version 4.6.7 or newer, which contains the official fix for the pointimage ACL bypass and stored XSS.
  • If an upgrade is not immediately possible, disable or remove the {{pointimage}} macro from the affected pages to prevent the upload of arbitrary content.
  • Audit existing wiki pages for injected HTML or JavaScript and manually remove any malicious code found.
  • Monitor audit logs for unexpected POST requests to the pointimage action and enforce stricter ACL checks if possible.

Generated by OpenCVE AI on October 2, 2026 at 12:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains a missing authorization flaw in the pointimage action (tools/attach/actions/pointimage.php), which saves content to an attacker-chosen page with write ACL checks bypassed. Unauthenticated attackers can POST pagetag, title, and description fields to any page rendering {{pointimage}} to append raw HTML or JavaScript to any wiki page, including pages whose write ACL restricts editing, causing stored cross-site scripting in viewers' and administrators' browsers.
Title YesWiki before 4.6.7 ACL Bypass and Stored XSS via pointimage Action
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-79
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T14:52:29.719Z

Reserved: 2026-10-02T00:53:58.504Z

Link: CVE-2026-104450

cve-icon Vulnrichment

Updated: 2026-10-02T14:52:23.335Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:16.483

Modified: 2026-10-02T15:17:07.310

Link: CVE-2026-104450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')