Critical severityNVD Advisory· Published Sep 5, 2026· Updated Sep 8, 2026
CVE-2026-52777
CVE-2026-52777
Description
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
yeswiki/yeswikiPackagist | < 4.6.6 | 4.6.6 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.