YesWiki 是一个用 PHP 编写的 Wiki 系统。在 4.2.0 版本至 4.6.6 版本之前, 方法将从数据库中检索到的页面标签直接拼接进 查询语句中,且未进行转义处理。由于页面标签由攻击者控制—— 接口接受任意 URL 编码的值(包括单引号),并将其存储起来,因此一个低权限的已认证用户可以创建一个标签为 SQL 片段的页面,通过标准的 链接机制使该页面成为非孤立页面,然后调用删除端点,从而在 Wiki 数据库中执行任意 SQL 语句——甚至可以从任意表中通过基于时间的盲注方式提取数据。该问题已在 4.6
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52777 | 9.4 CRITICAL | YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize |
| CVE-2026-52766 | 9.1 CRITICAL | YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action |
| CVE-2026-52775 | 8.8 HIGH | YesWiki Authenticated SQL Injection in ReactionManager |
| CVE-2026-52769 | 8.3 HIGH | YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId` |
| CVE-2026-52767 | 8.2 HIGH | YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(.. |
| CVE-2026-52770 | 7.5 HIGH | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ye |
| CVE-2026-52762 | 7.1 HIGH | YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via |
| CVE-2026-52763 | 6.5 MEDIUM | YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitra |
| CVE-2026-52773 | 6.1 MEDIUM | Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` |
| CVE-2026-52774 | 6.1 MEDIUM | Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki |
| CVE-2026-52772 | 5.5 MEDIUM | YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.h |
No comments yet