PT-2026-57025 · Yeswiki+2 · Yeswiki+1

CVE-2026-52762

·

Published

2026-07-09

·

Updated

2026-09-05

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions YesWiki versions prior to 4.6.6
Description YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) in the semantic template feature. SSTI occurs when an application embeds user-supplied input into a server-side template without proper validation, allowing the execution of arbitrary code. This issue can be escalated to Remote Code Execution (RCE), where an attacker can execute arbitrary operating-system commands on the host server.
An authenticated administrator can inject arbitrary Twig expressions into the bn sem template (Semantic template (Twig)) or bn sem reverse template fields. This content is stored in the form configuration and subsequently executed server-side via the TemplateEngine::renderFromStringNoEscape() function when public semantic endpoints are requested, such as the endpoint /api/forms/{id}/entries/json-ld.
Recommendations Update YesWiki to version 4.6.6. As a temporary workaround, restrict access to the bn sem template and bn sem reverse template fields to prevent the injection of malicious Twig expressions.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52762
GHSA-65P8-9433-JPCP

Affected Products

Yeswiki
Yeswiki/Yeswiki