Products: 2
    Vulnerabilities: 32
    Known Exploited: 0
    8
    Critical Level Threats
    12
    High Level Threats
    9
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-52777

    YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize

    Last Modified: Sep 05, 2026
    Published: Sep 04, 2026

    CVE-2026-52775

    YesWiki Authenticated SQL Injection in ReactionManager

    Last Modified: Sep 05, 2026
    Published: Sep 04, 2026

    CVE-2026-52774

    Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki

    Last Modified: Sep 05, 2026
    Published: Sep 04, 2026

    CVE-2026-52773

    Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki

    Last Modified: Sep 05, 2026
    Published: Sep 04, 2026

    CVE-2026-52772

    YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and label-body contexts — stored XSS in form renders (sibling class of commit `e6b66aa`)

    Last Modified: Sep 05, 2026
    Published: Sep 04, 2026
    Items Per Page