CVE-2026-104461 | YesWiki up to 4.6.6 Bazar FileField /api/entries/{formId} cleanFile cross site scripting

SecurityVulns

A vulnerability labeled as problematic has been found in YesWiki up to 4.6.6. This vulnerability affects the function HtmlPurifierService::cleanFile of the file /api/entries/{formId} of the component Bazar FileField. Such manipulation leads to cross site scripting.

This vulnerability is listed as CVE-2026-104461. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More