CVE WATCH / VULNERABILITY DETAIL

CVE-2026-104471

HIGHCVSS 7.2NVD feed

Published 2 October 2026 · tracked since 3 October 2026

Description

YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV import preview. Attackers can import a CSV whose file or image field references a remote .php URL, which is saved with

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-104471 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-104471

HIGHCVSS 7.2NVD feed

Published 2 October 2026 · tracked since 3 October 2026

Description

YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV import preview. Attackers can import a CSV whose file or image field references a remote .php URL, which is saved with

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]