CVEs we hold for Yeswiki
Records whose assigning authority named Yeswiki as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-52778YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of Service (DoS)yeswiki
CVE-2026-52777YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserializeyeswiki
CVE-2026-52774Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWikiyeswiki
CVE-2026-52773Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWikiyeswiki
CVE-2026-52772YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and…yeswiki
CVE-2026-52771YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)yeswiki
CVE-2026-52770Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswikiyeswiki
CVE-2026-52769YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`yeswiki
CVE-2026-52767YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`yeswiki
CVE-2026-52766YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` actionyeswiki
CVE-2026-52763YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB readyeswiki
CVE-2026-52762YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templatesyeswiki
CVE-2026-41143YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()yeswiki
28 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.