Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

yeswiki — Vulnerabilities & Security Advisories 64

All 64 CVE vulnerabilities found in yeswiki, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the product yeswiki, covering specific weakness types and security advisories. It collects disclosed security issues affecting this software, detailing various bug classes and the time range during which these flaws were identified and patched. Readers can use this resource to track the vendor’s advisory history, understand recurring weakness categories impacting the product, and review the complete vulnerability timeline for yeswiki. The data supports security teams in assessing risk exposure and planning remediation efforts based on historical patterns and current threats.

Vendor: YesWiki

CVE ID Title CVSS Severity Published
CVE-2026-104443 YesWiki before 4.6.7 Scope Bypass via Triples Delete API CWE-863 8.1 High 2026-10-02
CVE-2026-104442 YesWiki before 4.6.7 Unauthenticated SSRF via syndication Action CWE-918 5.8 Medium 2026-10-02
CVE-2026-104440 YesWiki before 4.6.7 Blind SSRF via bazarlist API idtypeannonce Parameter CWE-918 5.3 Medium 2026-10-02
CVE-2026-104441 YesWiki before 4.6.7 Unauthenticated SSRF via valeur Action CWE-918 5.3 Medium 2026-10-02
CVE-2026-104438 YesWiki before 4.6.7 Information Disclosure via listpagestag and includepages Actions CWE-862 5.3 Medium 2026-10-02
CVE-2026-104439 YesWiki before 4.6.7 User Enumeration via Lost-Password Flow CWE-204 5.3 Medium 2026-10-02
CVE-2026-52777 YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize CWE-352 9.4 Critical 2026-09-04
CVE-2026-52775 YesWiki Authenticated SQL Injection in ReactionManager CWE-89 8.8 High 2026-09-04
CVE-2026-52774 Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki CWE-80 6.1 Medium 2026-09-04
CVE-2026-52773 Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki CWE-80 6.1 Medium 2026-09-04
CVE-2026-52772 YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and label-body contexts — stored XSS in form renders (sibling class of commit `e6b66aa`) CWE-79 5.5 Medium 2026-09-04
CVE-2026-52771 YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`) CWE-89 8.3 High 2026-09-04
CVE-2026-52770 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswiki CWE-89 7.5 High 2026-09-04
CVE-2026-52769 YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId` CWE-918 8.3 High 2026-09-04
CVE-2026-52767 YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)` CWE-347 8.2 High 2026-09-04
CVE-2026-52766 YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action CWE-276 9.1 Critical 2026-09-04
CVE-2026-52763 YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB read CWE-89 6.5 Medium 2026-09-04
CVE-2026-52762 YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates CWE-1336 7.1 High 2026-09-04
CVE-2026-46670 YesWiki: Unauthenticated SQL Injection CWE-89 9.8 Critical 2026-08-11
CVE-2026-52778 YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of Service (DoS) CWE-94 9.8 Critical 2026-06-08
CVE-2026-41143 YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave() CWE-89 8.8 High 2026-05-07
CVE-2026-34598 YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter" CWE-79 6.1AI Medium AI 2026-04-02
CVE-2025-46550 Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting CWE-79 4.3 Medium 2025-04-29
CVE-2025-46549 Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting CWE-79 4.3 Medium 2025-04-29
CVE-2025-46348 YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download CWE-287 10.0 Critical 2025-04-29
CVE-2025-46350 Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting CWE-79 3.5 Low 2025-04-29
CVE-2025-46349 YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting CWE-79 7.6 High 2025-04-29
CVE-2025-46347 YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution CWE-116 8.8AI High AI 2025-04-29
CVE-2025-46346 YesWiki Vulnerable to Stored XSS in Comments CWE-79 5.4AI Medium AI 2025-04-29
CVE-2025-31131 Path Traversal allowing arbitrary read of files in Yeswiki CWE-22 8.6 High 2025-04-01

All 64 known CVE vulnerabilities affecting yeswiki with full Chinese analysis, references, and POCs where available.