CVE & Vulnerabilities · September 7, 2026
A newly disclosed flaw in the YesWiki PHP wiki platform lets an authenticated administrator plant arbitrary Twig template code inside the Bazar module's semantic template field, which the server later runs whenever a public endpoint touches that data. Because the injected template logic executes server-side, researchers confirmed it can be escalated into full remote code execution. The issue, tracked as CVE-2026-52762, affects versions before 4.6.6, where it has now been fixed.
// source: nvd.nist.gov ↗