SQL Injection Vulnerability in YesWiki Affects Multiple Versions of the PHP-Based Wiki System
CVE-2026-52763
6.5MEDIUM
What is CVE-2026-52763?
YesWiki, a PHP-based wiki system, is vulnerable to a SQL injection that allows attackers to read arbitrary data from the database. The vulnerability arises from the handling of the recentchanges action prior to version 4.6.6, where insufficient validation of the period argument enables malicious input to bypass security measures. As a result, an attacker can trigger stored SQL injection by saving a specially crafted trigger page, leading to exposure of sensitive database content to any user accessing that page. This issue affects default installations where anonymous users can save pages, thus posing a significant risk. This vulnerability has been remediated in the latest update, version 4.6.6.
Affected Version(s)
yeswiki < 4.6.6
