YesWiki是法国YesWiki组织开源的一个面向团队的协作式内容管理平台。 YesWiki 4.1.0版本至4.6.6之前版本存在跨站脚本漏洞,该漏洞源于handlers/page/show.php中未对time GET参数进行转义处理,攻击者可利用MySQL对畸形DATETIME字符串的强制转换,向有效的存档修订时间戳追加HTML或JavaScript,导致在受害者浏览器中执行任意JavaScript脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coerces malformed DATETIME strings, an attacker can append an XSS payload after a valid revision timestamp. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-52773.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-52777 | 9.4 CRITICAL | YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize |
| CVE-2026-52766 | 9.1 CRITICAL | YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action |
| CVE-2026-52775 | 8.8 HIGH | YesWiki Authenticated SQL Injection in ReactionManager |
| CVE-2026-52769 | 8.3 HIGH | YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId` |
| CVE-2026-52771 | 8.3 HIGH | YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiControl |
| CVE-2026-52767 | 8.2 HIGH | YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(.. |
| CVE-2026-52770 | 7.5 HIGH | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ye |
| CVE-2026-52762 | 7.1 HIGH | YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via |
| CVE-2026-52763 | 6.5 MEDIUM | YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitra |
| CVE-2026-52774 | 6.1 MEDIUM | Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki |
| CVE-2026-52772 | 5.5 MEDIUM | YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.h |
No comments yet