Medium severity6.1NVD Advisory· Published Sep 9, 2025· Updated Jul 5, 2026
CVE-2025-52277
CVE-2025-52277
Description
Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted payload to the meta configuration robots field
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
yeswiki/yeswikiPackagist | <= 4.5.4 | — |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/nakkouchtarek/CVE/tree/main/CVE-2025-52277nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-29cj-cxw4-v4j2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-52277ghsaADVISORY
- yeswiki.comghsaWEB
News mentions
0No linked articles in our index yet.