yeswiki/yeswiki vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-52778Criticalyeswiki/yeswiki: YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of ServiceCVE-2026-52777Criticalyeswiki/yeswiki: YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserializeCVE-2026-52775Highyeswiki/yeswiki: YesWiki has Authenticated SQL Injection via ReactionManager CVE-2026-52774Mediumyeswiki/yeswiki: YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML AttributesCVE-2026-52773Mediumyeswiki/yeswiki: YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php`CVE-2026-52772Mediumyeswiki/yeswiki: YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html'))CVE-2026-52771Highyeswiki/yeswiki: YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)CVE-2026-52770Highyeswiki/yeswiki: YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filtersCVE-2026-52769Highyeswiki/yeswiki: YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`CVE-2026-52767Highyeswiki/yeswiki: YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`CVE-2026-52766Criticalyeswiki/yeswiki: YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` actionCVE-2026-52763Mediumyeswiki/yeswiki: YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB readCVE-2026-52762Highyeswiki/yeswiki: YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic TemplatesCVE-2026-46670Criticalyeswiki/yeswiki: YesWiki: Unauthenticated SQL InjectionCVE-2026-41143Highyeswiki/yeswiki: YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()GHSA-5724-X3RH-5QQQMediumyeswiki/yeswiki: YesWiki has Multiple Reflected Cross-site Scripting VulnerabilitiesCVE-2026-34598Highyeswiki/yeswiki: YesWiki has Persistent Blind XSS at "/?BazaR&vue=consulter"CVE-2025-52277Mediumyeswiki/yeswiki: YesWiki Cross Site Scripting vulnerabilityCVE-2025-46346Lowyeswiki/yeswiki: YesWiki Stored XSS Vulnerability in Comments CVE-2025-46347Highyeswiki/yeswiki: YesWiki Remote Code Execution via Arbitrary PHP File Write and ExecutionCVE-2025-46348Criticalyeswiki/yeswiki: YesWiki Vulnerable to Unauthenticated Site Backup Creation and DownloadCVE-2025-46349Highyeswiki/yeswiki: YesWiki Vulnerable to Unauthenticated Reflected Cross-site ScriptingCVE-2025-46350Lowyeswiki/yeswiki: Yeswiki Vulnerable to Authenticated Reflected Cross-site ScriptingCVE-2025-46550Mediumyeswiki/yeswiki: Yeswiki Vulnerable to Unauthenticated Reflected Cross-site ScriptingCVE-2025-46549Mediumyeswiki/yeswiki: Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting

Stop the waste.
Protect your environment with Kodem.