SQL Injection Vulnerability in YesWiki Affects Multiple Versions of the PHP-Based Wiki System
CVE-2026-52763

6.5MEDIUM

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-52763?

YesWiki, a PHP-based wiki system, is vulnerable to a SQL injection that allows attackers to read arbitrary data from the database. The vulnerability arises from the handling of the recentchanges action prior to version 4.6.6, where insufficient validation of the period argument enables malicious input to bypass security measures. As a result, an attacker can trigger stored SQL injection by saving a specially crafted trigger page, leading to exposure of sensitive database content to any user accessing that page. This issue affects default installations where anonymous users can save pages, thus posing a significant risk. This vulnerability has been remediated in the latest update, version 4.6.6.

Affected Version(s)

yeswiki < 4.6.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.