Sceawere

Vulnerability Detail

CVE-2026-104466UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or post comments to inject event handlers by placing quotes in markdown image URLs. Attackers can store a crafted markdown image whose src breaks out of the attribute to add an onerror handler, executing JavaScript in viewers' browsers, including administrators.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-02T12:17:19.217Z",
  "pubdate": "2026-10-02T12:17:19.217Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a stored cross-site scripting (XSS) vulnerability located within the application's markdown processing logic. This flaw allows authenticated users with page editing or comment posting privileges to inject arbitrary JavaScript into page content.\nThe vulnerability stems from improper neutralization of user-supplied input when processing markdown image URLs. By crafting a specifically formatted markdown image syntax, an attacker can break out of the HTML attribute context to inject malicious event handlers, such as 'onerror'.\nSuccessful exploitation results in the execution of JavaScript within the context of a victim's browser session. The potential impact is significant, as this can be leveraged to compromise session cookies, perform unauthorized actions on behalf of the user, or conduct further attacks against application administrators. Given the persistent nature of stored XSS, the payload remains active for any user accessing the affected page or comment, creating a continuous risk. Exploitation requires minimal privileges, specifically the ability to contribute content to the wiki.",
  "technicalDetails": "The vulnerability exists in the handling of markdown syntax within the formatters/wakka.php file in YesWiki versions prior to 4.6.7. The core issue is an inadequate sanitization of user-supplied input used to construct HTML image tags from markdown image syntax. Specifically, the application fails to properly escape or validate the source URL provided within the image markdown markup.\nWhen a user submits a markdown image tag, the application processes the URL to render an HTML <img> element. An attacker can exploit this by crafting a malicious payload that includes double quotes to terminate the 'src' attribute prematurely, followed by the injection of additional HTML attributes, such as the 'onerror' event handler. For example, a payload structured as '![alt](invalid_url\" onerror=\"alert(1)\")' is processed by formatters/wakka.php and rendered as '<img src=\"invalid_url\" onerror=\"alert(1)\" alt=\"alt\">' in the final HTML document.\nThe attack flow follows these steps: 1) The attacker crafts a payload utilizing markdown image syntax containing a malicious attribute injection sequence. 2) The attacker inserts this payload into a page, comment, or any component that utilizes the affected formatter. 3) The malicious payload is saved to the application's database. 4) When a victim—which may include an administrator or other high-privilege user—views the page or comment, the server delivers the malicious HTML to their browser. 5) The browser encounters the invalid 'src', triggering the 'onerror' event, which subsequently executes the attacker's injected JavaScript.\nBecause the payload is stored persistently in the database, the attack does not require direct interaction with the target user beyond their viewing of the compromised content. The injected script operates with the full privileges of the victim's session, allowing for actions such as theft of CSRF tokens, session hijacking, redirection to malicious domains, or unauthorized modifications to the wiki's content. The vulnerability is fundamentally a failure in the input validation and output encoding pipeline within the application's markdown formatting component, which fails to consider the security context of the attributes it constructs from user input."
}
CVE-2026-104466: YesWiki Stored XSS Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere