CVE-2026-52772

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders. This issue has been patched in version 4.6.6.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-05 00:17

Updated : 2026-09-09 18:16


NVD link : CVE-2026-52772

Mitre link : CVE-2026-52772

CVE.ORG link : CVE-2026-52772


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-116

Improper Encoding or Escaping of Output