CVE-2026-104461 | YesWiki up to 4.6.6 Bazar FileField /api/entries/{formId} cleanFile cross site scripting
A vulnerability labeled as problematic has been found in YesWiki up to 4.6.6. This vulnerability affects the function HtmlPurifierService::cleanFile of the file /api/entries/{formId} of the component Bazar FileField. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-104461. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More