CVE-2026-105224 Overview
CVE-2026-105224 is a stored cross-site scripting (XSS) vulnerability in YesWiki versions prior to 4.6.7. The flaw resides in the Bazar valeur action handler at tools/bazar/actions/valeur.php, which fetches content from a remote URL and renders it without escaping HTML output. Page editors can configure the action to pull BAZ_fiche_titre markup from an attacker-controlled server. The retrieved payload, such as an img tag with an onerror handler, executes JavaScript in the browser of every user who views the affected wiki page. The weakness is tracked as CWE-79.
Critical Impact
Any authenticated editor can plant persistent JavaScript that runs under the origin of the YesWiki instance, enabling session theft, credential harvesting, and account takeover of readers and administrators.
Affected Products
- YesWiki versions prior to 4.6.7
- Deployments exposing the tools/bazar/actions/valeur.php action
- Instances allowing untrusted editors to configure Bazar page actions
Discovery Timeline
- 2026-10-04 - CVE-2026-105224 published to NVD
- 2026-10-05 - Last updated in NVD database
Technical Details for CVE-2026-105224
Vulnerability Analysis
The Bazar module in YesWiki provides the valeur action to extract and display the content of a Bazar entry field from a URL supplied by the page editor. The pre-patch handler called file_get_contents() against the editor-supplied url parameter, appended /html, and injected the response directly into the rendered page. No sanitization or output encoding was applied to the fetched HTML. When the targeted field was bf_titre, the code emitted the remote BAZ_fiche_titre markup as-is into the DOM of the viewing user.
This creates a stored XSS primitive, because the malicious URL is persisted in the wiki page definition and re-fetched on every render. Any viewer, including administrators, executes attacker-controlled JavaScript in the context of the YesWiki origin. Impacts include session cookie theft, CSRF against privileged endpoints, and silent modification of other wiki content.
Root Cause
The root cause is missing output neutralization of untrusted data retrieved over the network. The handler trusted the remote endpoint's HTML and inserted it into the server-rendered page without applying HTML encoding or an allow-list parser. Combined with the ability of low-privileged editors to control the destination url, the trust boundary between the wiki server and arbitrary third-party content was effectively removed.
Attack Vector
Exploitation requires editor-level access to a YesWiki page and user interaction from a viewer. The attacker configures a Bazar valeur action pointing url at a server they control. That server returns a response containing a BAZ_fiche_titre block with an injected payload such as <img src=x onerror=...>. When any user loads the page, YesWiki fetches and renders the payload, executing script in the viewer's browser.
// Vulnerable logic in tools/bazar/actions/valeur.php (pre-patch)
$url = $this->GetParameter('url');
if (empty($url) && isset($this->config['source_url']) && !empty($this->config['source_url'])) {
$url = $this->config['source_url'];
}
if (!empty($url)) {
$champ = $this->GetParameter('champ');
if (!empty($champ)) {
if (!isset($GLOBALS['externalpage'][$url])) {
$GLOBALS['externalpage'][$url] = @file_get_contents($url . '/html');
}
if (!$GLOBALS['externalpage'][$url] === false) {
// the title field is a special case
if ($champ == 'bf_titre') {
// BAZ_fiche_titre markup rendered without escaping
}
}
}
}
Source: YesWiki security patch commit 22a5260
Detection Methods for CVE-2026-105224
Indicators of Compromise
- Bazar page definitions referencing a valeur action whose url parameter points to an external, non-corporate domain.
- Outbound HTTP requests from the YesWiki server to unexpected hosts with the path suffix /html.
- Wiki responses containing BAZ_fiche_titre markup paired with inline event handlers such as onerror, onload, or onclick.
- Session or administrative actions originating from browsers immediately after viewing a modified Bazar-enabled page.
Detection Strategies
- Inspect page content and database records for {{valeur ... url="http..."}} directives and flag URLs outside an approved list.
- Enable web server access logging on the YesWiki host and review outbound file_get_contents traffic for anomalous destinations.
- Deploy a Content Security Policy (CSP) in report-only mode to surface inline script executions originating from rendered wiki pages.
Monitoring Recommendations
- Monitor YesWiki PHP error and access logs for repeated remote fetches tied to editor accounts.
- Alert on new or modified wiki pages that introduce valeur actions, especially from accounts with recent privilege changes.
- Track administrator session activity for unusual API calls shortly after page views, which may indicate XSS-driven CSRF.
How to Mitigate CVE-2026-105224
Immediate Actions Required
- Upgrade YesWiki to version 4.6.7 or later, which refactors the valeur action and applies the fix from GHSA-6rvf-7pwm-6j44.
- Audit existing wiki pages for valeur actions referencing untrusted URLs and remove or rewrite them.
- Rotate session cookies and administrative credentials if exploitation is suspected.
Patch Information
The maintainers fixed the issue in YesWiki 4.6.7 via commit 22a5260b0381824e01d340ce9457c4adb9e18b23. The patch refactors tools/bazar/actions/valeur.php so that remotely fetched content is no longer rendered as raw HTML. Additional context is available in the VulnCheck advisory.
Workarounds
- Restrict editor permissions so that only trusted users can create or modify Bazar actions on wiki pages.
- Use a reverse-proxy allow-list to block outbound HTTP requests from the YesWiki host to arbitrary destinations.
- Deploy a strict Content Security Policy that disallows inline event handlers and unapproved script sources.
# Upgrade YesWiki to the patched release
cd /var/www/yeswiki
git fetch --tags
git checkout 4.6.7
# Clear cached templates after upgrade
rm -rf cache/*
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.