PatchSiren

YesWiki CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL YesWiki CVE published 2026-08-11

CVE-2026-46670

A critical vulnerability exists in YesWiki, a wiki system written in PHP, prior to version 4.6.4. An unauthenticated SQL injection in the Bazar form-import path allows arbitrary SQL injection into an INSERT statement, enabling any unauthenticated visitor to read the full database, including yeswiki_users.password hashes. This vulnerability has significant implications for the security of YesWiki installat [truncated]

CRITICAL YesWiki CVE published 2026-06-08

CVE-2026-52778

A critical vulnerability (CVSS Score: 9.8) exists in YesWiki's Bazar form field calculator (CalcField.php) prior to version 4.6.6. The application attempts to sanitize user-defined mathematical formulas using a complex recursive regular expression before passing them to the PHP eval() function. However, this implementation is flawed, making it vulnerable to Regular Expression Denial of Service (ReDoS / St [truncated]