Skip to content

Menu
  • Home
Menu

CVE-2026-52775 – YesWiki Authenticated SQL Injection in ReactionManager

Posted on September 5, 2026
CVE ID :CVE-2026-52775

Published : Sept. 5, 2026, 12:17 a.m. | 20 minutes ago

Description :YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary SQL via the {idreaction} and {id} URL path parameters. The parameters are concatenated directly into a SQL LIKE clause without escaping or parameterization. This issue has been patched in version 4.6.6.

Severity: 8.8 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Post Views: 1

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme