CVE-2026-52777

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-05 00:17

Updated : 2026-09-08 21:05


NVD link : CVE-2026-52777

Mitre link : CVE-2026-52777

CVE.ORG link : CVE-2026-52777


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-502

Deserialization of Untrusted Data