CVE-2026-104440 | YesWiki up to 4.6.6 Bazar /api/entries/bazarlist isValidURL idtypeannonce server-side request forgery

SecurityVulns

A vulnerability was found in YesWiki up to 4.6.6. It has been declared as problematic. The impacted element is the function isValidURL of the file /api/entries/bazarlist of the component Bazar. Such manipulation of the argument idtypeannonce leads to server-side request forgery.

This vulnerability is referenced as CVE-2026-104440. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More