OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-104471 (CVSS 8.6)

NVD · officialPublished Oct 2, 2026Risk 37/100

YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV import preview. Attackers can import a CSV whose file or image field references a remote .php URL, which is saved without extension checks and executed as server-side code.

CVSS
8.6
AV:NetworkAC:LowPR:HighUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source