CVE-2026-52777
9.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| YesWiki | yeswiki | < 4.6.6 | affected |
Weaknesses
- CWE-352: CWE-352: Cross-Site Request Forgery (CSRF)
- CWE-502: CWE-502: Deserialization of Untrusted Data
References
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-9369-69wj-7m2f
- https://github.com/YesWiki/yeswiki/commit/8f70a8d6b8befa0e644d03c785701dbbc55b8fd0
- https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.