MEDIUM 6.9 NVD
CVE-2026-104442
YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs
YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication action through the render handler's content parameter. Attackers can target internal hosts and ports, read back fetched feed content in the rendered page, and cause feed enclosures to be downloaded into the files directory.
References
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-jwh5-j4f4-c6xp
- https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-unauthenticated-ssrf-via-syndica
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-10-02 via NVD.
vulnfeed aggregates 10476 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.