Stored XSS Vulnerability in YesWiki Wiki System
CVE-2026-52772

5.5MEDIUM

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-52772?

YesWiki, a PHP-based wiki system, is vulnerable to stored Cross-Site Scripting (XSS) due to improper handling of form-field templates in versions prior to 4.6.6. The vulnerability arises from the application applying |raw('html') to field labels and hints within attribute and label-body contexts. This flaw can allow attackers to inject malicious scripts into web pages, potentially affecting end users. Users are strongly advised to upgrade to version 4.6.6 or later, where this issue has been addressed.

Affected Version(s)

yeswiki < 4.6.6

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.