CVE-2026-104473 Overview
CVE-2026-104473 is a reflected Cross-Site Scripting (XSS) vulnerability [CWE-79] affecting YesWiki versions prior to 4.5.3. The flaw exists in multiple unsanitized request parameters including incomingurl, id, file, tags, and template within the bazar and listpages functionality. Remote attackers can craft malicious URLs that inject JavaScript into the victim's browser session. Successful exploitation enables session hijacking and the execution of authenticated requests against backend wiki functionality.
Critical Impact
Attackers can execute arbitrary JavaScript in a victim's browser context, hijack authenticated sessions, and trigger privileged actions against YesWiki installations through crafted links.
Affected Products
- YesWiki versions prior to 4.5.3
- YesWiki bazar component (parameters: incomingurl, id, file, tags)
- YesWiki listpages component (parameter: template)
Discovery Timeline
- 2026-10-02 - CVE-2026-104473 published to NVD
- 2026-10-08 - Last updated in NVD database
Technical Details for CVE-2026-104473
Vulnerability Analysis
YesWiki is a PHP-based collaborative wiki platform. Versions before 4.5.3 fail to sanitize several user-controlled query parameters before reflecting their values into rendered HTML output. The affected parameters are processed by the bazar and listpages modules, which handle resource listings and page templating.
When a victim loads a crafted URL, the injected payload executes within the browser's trust context for the YesWiki origin. Because the attack reflects immediately in the response, no persistent storage on the server is required. The vulnerability is categorized under CWE-79: Improper Neutralization of Input During Web Page Generation.
Root Cause
The root cause is missing output encoding and input validation on parameters passed to the bazar and listpages request handlers. User input flows directly into HTML or JavaScript contexts without contextual escaping. Developers did not apply HTML entity encoding or an allowlist filter to attributes such as incomingurl, id, file, tags, and template.
Attack Vector
Exploitation requires user interaction: the victim must click a crafted link or visit an attacker-controlled page that triggers the request. Once loaded, the reflected payload runs in the victim's browser session. If the victim is authenticated, the attacker can issue authenticated requests, read session tokens accessible to JavaScript, or pivot to administrative wiki functions. Unauthenticated victims can still be targeted to steal CSRF tokens or redirect sessions.
See the GitHub Security Advisory GHSA-5724-x3rh-5qqq and the VulnCheck Advisory for YesWiki XSS for parameter-specific details.
Detection Methods for CVE-2026-104473
Indicators of Compromise
- HTTP GET requests to YesWiki endpoints containing <script>, javascript:, onerror=, or onload= substrings in the incomingurl, id, file, tags, or template parameters.
- Access log entries showing URL-encoded payloads such as %3Cscript%3E or %22%3E%3Csvg targeting bazar or listpages routes.
- Unexpected outbound requests from authenticated wiki sessions immediately following a user clicking an external link.
Detection Strategies
- Deploy web application firewall rules that inspect query strings for HTML tag characters and common XSS payload patterns on the affected parameters.
- Review web server access logs for anomalous Referer headers pointing to external domains preceding requests to bazar or listpages handlers.
- Correlate browser-side Content Security Policy (CSP) violation reports with authenticated session identifiers to spot inline script execution attempts.
Monitoring Recommendations
- Alert on sudden spikes in requests to YesWiki URLs carrying encoded angle brackets or JavaScript URI schemes.
- Track administrative actions performed shortly after a user session loads a reflected parameter containing suspicious characters.
- Monitor for session token reuse from new IP addresses or user-agent strings as a possible indicator of hijacked sessions.
How to Mitigate CVE-2026-104473
Immediate Actions Required
- Upgrade YesWiki to version 4.5.3 or later on all production and staging instances.
- Audit YesWiki web server logs for prior exploitation attempts against bazar and listpages parameters.
- Invalidate active user sessions and require re-authentication after patching to limit the impact of any stolen tokens.
Patch Information
The YesWiki maintainers released version 4.5.3 containing fixes for the reflected XSS issues. Refer to the GitHub Security Advisory GHSA-5724-x3rh-5qqq for the full fix commit list and upgrade guidance.
Workarounds
- Restrict access to the YesWiki administrative interface by source IP until the upgrade is applied.
- Deploy a Content Security Policy (CSP) that disallows inline scripts and restricts script-src to trusted origins to blunt reflected payloads.
- Place a WAF rule in front of YesWiki to block requests containing <, >, or javascript: sequences in the incomingurl, id, file, tags, and template parameters.
# Example nginx rule to drop requests with angle brackets in vulnerable parameters
if ($args ~* "(incomingurl|id|file|tags|template)=[^&]*(%3C|%3E|<|>|javascript:)") {
return 403;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.