YesWiki 是一个用 PHP 编写的维基系统。在 4.6.6 版本之前, 动作( )接受来自两个互不重叠的参数空间的 参数。白名单仅对 URL 形式的参数进行校验,允许值为 。而对于动作参数形式(即通过表单或动作调用传入的 ),代码走的是 分支,未做任何校验。该参数值直接传入 ,并被直接插值拼接到 SQL 语句的 子句中,既没有转义也没有使用参数化查询。 攻击者可通过基于 的注入成功读取数据库行,泄露的数据会渲染在响应页面中,因此任何访问触发页面的用户都能看到外泄的数据。该漏洞使得任何能够保存触发页面的用户(包
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52777 | 9.4 CRITICAL | YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize |
| CVE-2026-52766 | 9.1 CRITICAL | YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action |
| CVE-2026-52775 | 8.8 HIGH | YesWiki Authenticated SQL Injection in ReactionManager |
| CVE-2026-52769 | 8.3 HIGH | YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId` |
| CVE-2026-52771 | 8.3 HIGH | YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiControl |
| CVE-2026-52767 | 8.2 HIGH | YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(.. |
| CVE-2026-52770 | 7.5 HIGH | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ye |
| CVE-2026-52762 | 7.1 HIGH | YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via |
| CVE-2026-52773 | 6.1 MEDIUM | Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` |
| CVE-2026-52774 | 6.1 MEDIUM | Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki |
| CVE-2026-52772 | 5.5 MEDIUM | YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.h |
No comments yet