CVE-2026-52773
- EPSS -
- Veröffentlicht 04.09.2026 23:44:39
- Zuletzt bearbeitet 08.09.2026 21:05:26
YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coerces malformed...
CVE-2026-52772
- EPSS -
- Veröffentlicht 04.09.2026 23:42:39
- Zuletzt bearbeitet 09.09.2026 18:16:58
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders. This issue has been patched i...
CVE-2026-52771
- EPSS -
- Veröffentlicht 04.09.2026 23:41:34
- Zuletzt bearbeitet 08.09.2026 21:05:26
YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' query without escaping. The page tag...
CVE-2026-52770
- EPSS -
- Veröffentlicht 04.09.2026 23:41:14
- Zuletzt bearbeitet 08.09.2026 21:05:26
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query / queries filters. For Bazar fields whose value structure is numeric, YesWiki ...
CVE-2026-52769
- EPSS -
- Veröffentlicht 04.09.2026 23:40:58
- Zuletzt bearbeitet 08.09.2026 21:05:26
YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - accepts an HTTP Signature header whose keyId parameter is a URL. HttpSignatureS...
CVE-2026-52767
- EPSS -
- Veröffentlicht 04.09.2026 23:40:39
- Zuletzt bearbeitet 08.09.2026 21:05:26
YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ... }. PHP's op...
CVE-2026-52766
- EPSS -
- Veröffentlicht 04.09.2026 23:40:12
- Zuletzt bearbeitet 09.09.2026 17:17:22
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no au...
CVE-2026-52763
- EPSS -
- Veröffentlicht 04.09.2026 23:39:53
- Zuletzt bearbeitet 08.09.2026 21:05:26
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter spaces. A whitelist validates only the URL form against ['day','week','month']...
CVE-2026-52762
- EPSS -
- Veröffentlicht 04.09.2026 23:39:36
- Zuletzt bearbeitet 08.09.2026 21:05:26
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic template feature that can be escalated to confirmed Remote Code Execution (RCE). An a...
CVE-2026-46670
- EPSS 1.65%
- Veröffentlicht 11.08.2026 13:58:32
- Zuletzt bearbeitet 09.09.2026 20:46:02
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an...