CVE-2026-104440 | YesWiki up to 4.6.6 Bazar /api/entries/bazarlist isValidURL idtypeannonce server-side request forgery
A vulnerability was found in YesWiki up to 4.6.6. It has been declared as problematic. The impacted element is the function isValidURL of the file /api/entries/bazarlist of the component Bazar. Such manipulation of the argument idtypeannonce leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-104440. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More