Authenticated PHP Object Injection in YesWiki by YesWiki
CVE-2026-52777
9.4CRITICAL
What is CVE-2026-52777?
YesWiki, a PHP-based wiki system, contains a vulnerability that allows authenticated users to exploit the BazarImportAction feature using the unserialize function. This vulnerability can lead to potential code execution or data manipulation. A patch has been applied in version 4.6.6, resolving this critical issue and enhancing the overall security of the application.
Affected Version(s)
yeswiki < 4.6.6
