Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

YesWiki — Vulnerabilities & Security Advisories 64

Browse all 64 CVE security advisories affecting YesWiki. AI-powered Chinese analysis, POCs, and references for each vulnerability.

YesWiki is a collaborative wiki platform designed for knowledge sharing and collective content creation. Historically, it has been vulnerable to multiple security issues including remote code execution (RCE), cross-site scripting (XSS), privilege escalation, and path traversal vulnerabilities, with 14 CVEs documented to date. These vulnerabilities often stem from insufficient input validation, improper access controls, and insecure default configurations. While no major public security incidents have been widely reported, the consistent discovery of vulnerabilities suggests ongoing security challenges. The platform's open-source nature allows for community-driven improvements, but users must remain vigilant about applying security patches and hardening configurations to mitigate potential risks.

Top products by YesWiki: yeswiki
CVE ID Title CVSS Severity Published
CVE-2026-104443 YesWiki before 4.6.7 Scope Bypass via Triples Delete API — yeswiki CWE-863 8.1 High 2026-10-02
CVE-2026-104442 YesWiki before 4.6.7 Unauthenticated SSRF via syndication Action — yeswiki CWE-918 5.8 Medium 2026-10-02
CVE-2026-104440 YesWiki before 4.6.7 Blind SSRF via bazarlist API idtypeannonce Parameter — yeswiki CWE-918 5.3 Medium 2026-10-02
CVE-2026-104441 YesWiki before 4.6.7 Unauthenticated SSRF via valeur Action — yeswiki CWE-918 5.3 Medium 2026-10-02
CVE-2026-104438 YesWiki before 4.6.7 Information Disclosure via listpagestag and includepages Actions — yeswiki CWE-862 5.3 Medium 2026-10-02
CVE-2026-104439 YesWiki before 4.6.7 User Enumeration via Lost-Password Flow — yeswiki CWE-204 5.3 Medium 2026-10-02
CVE-2026-52777 YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize — yeswiki CWE-352 9.4 Critical 2026-09-04
CVE-2026-52775 YesWiki Authenticated SQL Injection in ReactionManager — yeswiki CWE-89 8.8 High 2026-09-04
CVE-2026-52774 Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki — yeswiki CWE-80 6.1 Medium 2026-09-04
CVE-2026-52773 Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki — yeswiki CWE-80 6.1 Medium 2026-09-04
CVE-2026-52772 YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and label-body contexts — stored XSS in form renders (sibling class of commit `e6b66aa`) — yeswiki CWE-79 5.5 Medium 2026-09-04
CVE-2026-52771 YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`) — yeswiki CWE-89 8.3 High 2026-09-04
CVE-2026-52770 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswiki — yeswiki CWE-89 7.5 High 2026-09-04
CVE-2026-52769 YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId` — yeswiki CWE-918 8.3 High 2026-09-04
CVE-2026-52767 YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)` — yeswiki CWE-347 8.2 High 2026-09-04
CVE-2026-52766 YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action — yeswiki CWE-276 9.1 Critical 2026-09-04
CVE-2026-52763 YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB read — yeswiki CWE-89 6.5 Medium 2026-09-04
CVE-2026-52762 YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates — yeswiki CWE-1336 7.1 High 2026-09-04
CVE-2026-46670 YesWiki: Unauthenticated SQL Injection — yeswiki CWE-89 9.8 Critical 2026-08-11
CVE-2026-52778 YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of Service (DoS) — yeswiki CWE-94 9.8 Critical 2026-06-08
CVE-2026-41143 YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave() — yeswiki CWE-89 8.8 High 2026-05-07
CVE-2026-34598 YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter" — yeswiki CWE-79 6.1AI Medium AI 2026-04-02
CVE-2025-46550 Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting — yeswiki CWE-79 4.3 Medium 2025-04-29
CVE-2025-46549 Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting — yeswiki CWE-79 4.3 Medium 2025-04-29
CVE-2025-46348 YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download — yeswiki CWE-287 10.0 Critical 2025-04-29
CVE-2025-46350 Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting — yeswiki CWE-79 3.5 Low 2025-04-29
CVE-2025-46349 YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting — yeswiki CWE-79 7.6 High 2025-04-29
CVE-2025-46347 YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution — yeswiki CWE-116 8.8AI High AI 2025-04-29
CVE-2025-46346 YesWiki Vulnerable to Stored XSS in Comments — yeswiki CWE-79 5.4AI Medium AI 2025-04-29
CVE-2025-31131 Path Traversal allowing arbitrary read of files in Yeswiki — yeswiki CWE-22 8.6 High 2025-04-01

This page lists every published CVE security advisory associated with YesWiki. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.