Description
YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by rendering unescaped HTML fetched from a remote URL. Attackers can point tools/bazar/actions/valeur.php at a controlled server returning BAZ_fiche_titre markup with an img onerror handler, executing script in every viewer's browser.
Published: 2026-10-04
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Stored XSS via unescaped remote content
Action: Apply Patch
AI Analysis

Impact

YesWiki versions before 4.6.7 contain a stored cross‑site scripting flaw in the Bazar valeur action. Page editors can supply a remote URL that returns BAZ_fiche_titre markup with an image tag containing an onerror handler or other JavaScript. When the page is rendered, the unescaped HTML is inserted directly into the page, allowing arbitrary script execution in the browser of any user who views the page. This weakness is a classic input validation failure (CWE‑79) and based on the description, it is inferred that attackers could use the stored XSS to hijack sessions, steal credentials, or deliver malware through the victim’s browser.

Affected Systems

Any installation of YesWiki running a version older than 4.6.7 that includes the Bazar plugin is affected. Attackers may target the Bazar valeur action endpoint exposed under tools/bazar/actions/valeur.php.

Risk and Exploitability

The vulnerability scores a CVSS of 5.1, indicating medium severity, and no EPSS data is currently available. It is not listed in CISA’s KEV catalog. Exploitation requires the attacker to have editing privileges or the ability to trigger the Bazar action with a crafted remote URL, so the likely attack vector is limited to trusted users or compromised accounts. Nevertheless, the stored XSS payload will execute for every user who views the affected page, potentially exposing sensitive data or facilitating further attacks.

Generated by OpenCVE AI on October 4, 2026 at 17:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to YesWiki 4.6.7 or later, which removes the vulnerable code path.
  • Limit the use of the Bazar valeur action to trusted administrators or disable it if not needed.
  • Apply a Content‑Security Policy that blocks inline scripts or disallows execution of data‑URL or file‑URL schemas, reducing the impact of any remaining reflected content.

Generated by OpenCVE AI on October 4, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by rendering unescaped HTML fetched from a remote URL. Attackers can point tools/bazar/actions/valeur.php at a controlled server returning BAZ_fiche_titre markup with an img onerror handler, executing script in every viewer's browser.
Title YesWiki before 4.6.7 Stored XSS via Bazar valeur Action
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-79
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T15:04:53.749Z

Reserved: 2026-10-04T13:04:00.479Z

Link: CVE-2026-105224

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-04T16:16:30.470

Modified: 2026-10-04T16:16:30.597

Link: CVE-2026-105224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T18:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')