CVE-2026-104464
- EPSS 0.29%
- Veröffentlicht 02.10.2026 11:38:31
- Zuletzt bearbeitet 02.10.2026 15:17:08
YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to the Bazar abonnements sync action. Attackers can target internal...
CVE-2026-104463
- EPSS 0.25%
- Veröffentlicht 02.10.2026 11:38:30
- Zuletzt bearbeitet 02.10.2026 14:17:09
YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending signed Follow activities to the public forms actor inbox route. Attackers sign requests with their o...
CVE-2026-104462
- EPSS 0.31%
- Veröffentlicht 02.10.2026 11:38:30
- Zuletzt bearbeitet 02.10.2026 15:17:08
YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. Attackers with page-write access (unauthenticated on default installs) can embed a nu...
CVE-2026-104461
- EPSS 0.17%
- Veröffentlicht 02.10.2026 11:38:29
- Zuletzt bearbeitet 06.10.2026 17:17:13
YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extension and never calls HtmlPurifierService::cleanFile, so SVG files are stored verbatim and served inline as i...
CVE-2026-104460
- EPSS 0.39%
- Veröffentlicht 02.10.2026 11:38:28
- Zuletzt bearbeitet 02.10.2026 15:17:07
YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in actions/newtextsearch.php without escaping. Anonymous attackers can plant...
CVE-2026-104459
- EPSS 0.39%
- Veröffentlicht 02.10.2026 11:38:28
- Zuletzt bearbeitet 02.10.2026 14:17:08
YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService that allows unauthenticated attackers to trigger HTTPS requests to internal hosts. Attackers can POST a crafted actor_handle with a numeric host and port to...
CVE-2026-104458
- EPSS 0.32%
- Veröffentlicht 02.10.2026 11:38:27
- Zuletzt bearbeitet 02.10.2026 15:17:07
YesWiki before 4.6.7 contains a server-side request forgery vulnerability in validateKeyIdUrl() that allows unauthenticated attackers to bypass the SSRF guard using 6to4, NAT64, or IPv4-compatible IPv6 addresses. Attackers can send a crafted Signatur...
CVE-2026-104457
- EPSS 0.28%
- Veröffentlicht 02.10.2026 11:38:27
- Zuletzt bearbeitet 06.10.2026 17:17:12
YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default in...
CVE-2026-104456
- EPSS 0.3%
- Veröffentlicht 02.10.2026 11:38:26
- Zuletzt bearbeitet 02.10.2026 15:17:07
YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is concatenated unescaped into a read-ACL LIKE clause. Attackers can self-register an account name containing a doub...
CVE-2026-104455
- EPSS 0.37%
- Veröffentlicht 02.10.2026 11:38:25
- Zuletzt bearbeitet 02.10.2026 14:17:08
YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content via the recentchangesrssplus RSS action. Attackers can request the xml method of a page hosting the action to r...