YesWiki 是一个用 PHP 编写的 Wiki 系统。从版本 4.6.2 到早于 4.6.6 的版本中, 路由以 对外公开暴露。该路由接受一个 方法会解析该头部,并在进行任何密码学验证或 URL 校验之前,立即向 参数指定的 URL 发起服务器端 HTTP GET 请求。因此,未认证的远程攻击者可以诱导 YesWiki 向服务器能够访问的任意主机发起任意外部 HTTP 请求——例如内部服务、云元数据端点(169.254.169.254)、仅限内网的管理面板等——并通过时序差异和错误信息作为提示(oracle),
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52777 | 9.4 CRITICAL | YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize |
| CVE-2026-52766 | 9.1 CRITICAL | YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action |
| CVE-2026-52775 | 8.8 HIGH | YesWiki Authenticated SQL Injection in ReactionManager |
| CVE-2026-52771 | 8.3 HIGH | YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiControl |
| CVE-2026-52767 | 8.2 HIGH | YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(.. |
| CVE-2026-52770 | 7.5 HIGH | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ye |
| CVE-2026-52762 | 7.1 HIGH | YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via |
| CVE-2026-52763 | 6.5 MEDIUM | YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitra |
| CVE-2026-52773 | 6.1 MEDIUM | Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` |
| CVE-2026-52774 | 6.1 MEDIUM | Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki |
| CVE-2026-52772 | 5.5 MEDIUM | YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.h |
No comments yet