PT-2026-57025 · Yeswiki+2 · Yeswiki+1
CVE-2026-52762
·
Published
2026-07-09
·
Updated
2026-09-05
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
YesWiki versions prior to 4.6.6
Description
YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) in the semantic template feature. SSTI occurs when an application embeds user-supplied input into a server-side template without proper validation, allowing the execution of arbitrary code. This issue can be escalated to Remote Code Execution (RCE), where an attacker can execute arbitrary operating-system commands on the host server.
An authenticated administrator can inject arbitrary Twig expressions into the
bn sem template (Semantic template (Twig)) or bn sem reverse template fields. This content is stored in the form configuration and subsequently executed server-side via the TemplateEngine::renderFromStringNoEscape() function when public semantic endpoints are requested, such as the endpoint /api/forms/{id}/entries/json-ld.Recommendations
Update YesWiki to version 4.6.6.
As a temporary workaround, restrict access to the
bn sem template and bn sem reverse template fields to prevent the injection of malicious Twig expressions.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yeswiki
Yeswiki/Yeswiki