Stored Server-Side Template Injection in YesWiki Bazar by YesWiki
CVE-2026-52762

7.1HIGH

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-52762?

YesWiki Bazar, a PHP-based wiki system, is susceptible to a stored server-side template injection vulnerability due to improper handling of user input in the semantic template feature. An authenticated administrator can exploit this vulnerability by injecting arbitrary Twig expressions into the semantic template field, which will then be executed server-side when public semantic endpoints are accessed. This could lead to remote code execution, making it critical for users to upgrade to version 4.6.6, where this issue has been addressed.

Affected Version(s)

yeswiki < 4.6.6

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.