Unauthenticated SQL Injection Vulnerability in YesWiki Bazar Entry APIs
CVE-2026-52770
7.5HIGH
What is CVE-2026-52770?
YesWiki, a PHP-based wiki system, contains a vulnerability in its Bazar entry-listing APIs prior to version 4.6.6, allowing unauthenticated SQL injection through numeric query filters. The system fails to adequately escape and validate the attacker-controlled input, enabling potential attackers to execute arbitrary boolean SQL expressions. This could allow unauthorized access to sensitive database information based on the results of these queries. The issue has been resolved in version 4.6.6, emphasizing the importance of maintaining updated software to safeguard against such vulnerabilities.
Affected Version(s)
yeswiki < 4.6.6
