Stored XSS Vulnerability in YesWiki Wiki System
CVE-2026-52772
5.5MEDIUM
What is CVE-2026-52772?
YesWiki, a PHP-based wiki system, is vulnerable to stored Cross-Site Scripting (XSS) due to improper handling of form-field templates in versions prior to 4.6.6. The vulnerability arises from the application applying |raw('html') to field labels and hints within attribute and label-body contexts. This flaw can allow attackers to inject malicious scripts into web pages, potentially affecting end users. Users are strongly advised to upgrade to version 4.6.6 or later, where this issue has been addressed.
Affected Version(s)
yeswiki < 4.6.6
