CVE-2026-104471
HIGH
NVD
CVSS Score
7.2
Severity
HIGH
Published
Oct 02, 2026
Vendor
unknown
Description
YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV import preview. Attackers can import a CSV whose file or image field references a remote .php URL, which is saved without extension checks and executed as server-side code.