PT-2026-57033 · Yeswiki+2 · Yeswiki+1
CVE-2026-52773
·
Published
2026-07-09
·
Updated
2026-09-05
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
YesWiki versions 4.1.0 through 4.6.5
Description
YesWiki contains a reflected Cross-site Scripting (XSS) issue in the archived-revision view. The application reflects the
time GET parameter into a hidden HTML input within the 'handlers/page/show.php' endpoint without proper escaping. Because MySQL coerces malformed DATETIME strings, an attacker can append HTML or JavaScript to a valid archived revision timestamp. This allows the archived revision to still load while executing arbitrary JavaScript in the victim's browser.This issue is reachable when the following conditions are met:
- The target page has at least one archived revision.
- The victim has both
readandwriteaccess to the target page.
In certain configurations, such as default installations of doryphore 4.6.5, public pages may be editable anonymously, potentially affecting unauthenticated visitors.
Recommendations
Update YesWiki to version 4.6.6.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yeswiki
Yeswiki/Yeswiki