Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-52773— Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki

Quick assessment

Affected
YesWiki yeswiki
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

YesWiki是法国YesWiki组织开源的一个面向团队的协作式内容管理平台。 YesWiki 4.1.0版本至4.6.6之前版本存在跨站脚本漏洞,该漏洞源于handlers/page/show.php中未对time GET参数进行转义处理,攻击者可利用MySQL对畸形DATETIME字符串的强制转换,向有效的存档修订时间戳追加HTML或JavaScript,导致在受害者浏览器中执行任意JavaScript脚本。

CVSS 6.1 · Medium EPSS 0.59% · P46

Public Exploits 1

Affected Version Matrix 1

VendorProduct Version RangeStatus
YesWiki yeswiki >= 4.1.0, < 4.6.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-52773

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki
Source: CVE Program / CVE List V5
Vulnerability Description
YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coerces malformed DATETIME strings, an attacker can append HTML or JavaScript to a valid archived revision timestamp, still load that archived revision, and execute arbitrary JavaScript in the victim's browser. The vulnerable form is only rendered when the victim can both read and edit the target page. In restricted deployments this requires a victim with read and write access to that page. On a default doryphore 4.6.5 install, public pages such as PagePrincipale were editable anonymously during validation, so the issue can also affect unauthenticated visitors in that configuration. This issue has been patched in version 4.6.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
Web页面中脚本相关HTML标签转义处理不恰当(基本跨站脚本)
Source: CVE Program / CVE List V5
Vulnerability Title
YesWiki 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
YesWiki是法国YesWiki组织开源的一个面向团队的协作式内容管理平台。 YesWiki 4.1.0版本至4.6.6之前版本存在跨站脚本漏洞,该漏洞源于handlers/page/show.php中未对time GET参数进行转义处理,攻击者可利用MySQL对畸形DATETIME字符串的强制转换,向有效的存档修订时间戳追加HTML或JavaScript,导致在受害者浏览器中执行任意JavaScript脚本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
YesWiki yeswiki >= 4.1.0, < 4.6.6 -

II. Public POCs for CVE-2026-52773

# POC Description Source Link Shenlong Link
1 YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coerces malformed DATETIME strings, an attacker can append an XSS payload after a valid revision timestamp. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-52773.yaml POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52773

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-52773 (1)

Vendor Advisories for CVE-2026-52773 (1)

Other References for CVE-2026-52773 (1)

Same Patch Batch · YesWiki · 2026-09-04 · 12 CVEs total

CVE-2026-52777 9.4 CRITICAL YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize
CVE-2026-52766 9.1 CRITICAL YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action
CVE-2026-52775 8.8 HIGH YesWiki Authenticated SQL Injection in ReactionManager
CVE-2026-52769 8.3 HIGH YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`
CVE-2026-52771 8.3 HIGH YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiControl
CVE-2026-52767 8.2 HIGH YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(..
CVE-2026-52770 7.5 HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ye
CVE-2026-52762 7.1 HIGH YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via
CVE-2026-52763 6.5 MEDIUM YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitra
CVE-2026-52774 6.1 MEDIUM Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki
CVE-2026-52772 5.5 MEDIUM YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.h

IV. Related Vulnerabilities

V. Comments for CVE-2026-52773

No comments yet


Leave a comment