CVE-2026-52772
Dashboard / Vulnerabilities / CVE-2026-52772
Summary: YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and label-body contexts — stored XSS in form renders (sibling class of commit `e6b66aa`)
Details: YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders. This issue has been patched in version 4.6.6.
References: https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52772.json, https://github.com/YesWiki/yeswiki/security/advisories/GHSA-xc7j-3g8q-9vh4, https://nvd.nist.gov/vuln/detail/CVE-2026-52772, https://github.com/YesWiki/yeswiki/commit/5d1a4d07fecb0706f33e5dfbbe6ff5ef1892b2a7
Affected packages
Package
Name:
Purl:
