Stored Server-Side Template Injection in YesWiki Bazar by YesWiki
CVE-2026-52762
7.1HIGH
What is CVE-2026-52762?
YesWiki Bazar, a PHP-based wiki system, is susceptible to a stored server-side template injection vulnerability due to improper handling of user input in the semantic template feature. An authenticated administrator can exploit this vulnerability by injecting arbitrary Twig expressions into the semantic template field, which will then be executed server-side when public semantic endpoints are accessed. This could lead to remote code execution, making it critical for users to upgrade to version 4.6.6, where this issue has been addressed.
Affected Version(s)
yeswiki < 4.6.6
