{"id":"CVE-2026-52775","title":"YesWiki is a wiki system written in PHP","summary":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject a…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-89"],"vendor":"YesWiki","product":"yeswiki","affected":["yeswiki < 4.6.6"],"patched":["yeswiki/yeswiki 4.6.6"],"published":"2026-09-05","updated":"2026-09-08","sourceUpdated":"2026-09-08T21:05:26.920","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-52775","references":[{"url":"https://github.com/YesWiki/yeswiki/commit/90ca54fb518e1c43a1ead6e4f5bf9f0389789841","label":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","label":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-4pf7-cc4r-g63h","label":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-4pf7-cc4r-g63h","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-4pf7-cc4r-g63h"}],"tags":["nvd","cve.org","exploit-available","ghsa","composer"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-09-08T18:04:39.397368Z"},"epss":0.0029,"epssPercentile":0.21856,"aliases":["GHSA-4pf7-cc4r-g63h"],"ecosystem":"composer","ingestedAt":"2026-07-09T21:52:34.666Z","slug":"CVE-2026-52775","body":"## Overview\n\nYesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary SQL via the {idreaction} and {id} URL path parameters. The parameters are concatenated directly into a SQL LIKE clause without escaping or parameterization. This issue has been patched in version 4.6.6.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-52775)\n\nAffected packages:\n\n- `yeswiki/yeswiki < 4.6.6`\n\nPatched in:\n\n- `yeswiki/yeswiki 4.6.6`\n\nSource: https://github.com/advisories/GHSA-4pf7-cc4r-g63h","depth":"midnight","depthScore":60,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":8187,"id":"CVE-2026-52775","ts":1788919973003,"field":"exploit_available","old":"false","new":"true"},{"seq":7996,"id":"CVE-2026-52775","ts":1788919275440,"field":"exploit_available","old":"true","new":"false"},{"seq":7805,"id":"CVE-2026-52775","ts":1788916333609,"field":"exploit_available","old":"false","new":"true"},{"seq":7614,"id":"CVE-2026-52775","ts":1788915291682,"field":"exploit_available","old":"true","new":"false"},{"seq":7423,"id":"CVE-2026-52775","ts":1788912694854,"field":"exploit_available","old":"false","new":"true"},{"seq":7232,"id":"CVE-2026-52775","ts":1788911323970,"field":"exploit_available","old":"true","new":"false"},{"seq":7039,"id":"CVE-2026-52775","ts":1788909060931,"field":"exploit_available","old":"false","new":"true"},{"seq":6851,"id":"CVE-2026-52775","ts":1788907385540,"field":"exploit_available","old":"true","new":"false"},{"seq":6653,"id":"CVE-2026-52775","ts":1788905428331,"field":"exploit_available","old":"false","new":"true"},{"seq":6471,"id":"CVE-2026-52775","ts":1788903454668,"field":"exploit_available","old":"true","new":"false"},{"seq":6266,"id":"CVE-2026-52775","ts":1788901797321,"field":"exploit_available","old":"false","new":"true"},{"seq":6096,"id":"CVE-2026-52775","ts":1788899558068,"field":"exploit_available","old":"true","new":"false"},{"seq":5907,"id":"CVE-2026-52775","ts":1788898149134,"field":"exploit_available","old":"false","new":"true"},{"seq":5796,"id":"CVE-2026-52775","ts":1788895705203,"field":"exploit_available","old":"true","new":"false"},{"seq":5781,"id":"CVE-2026-52775","ts":1788894573512,"field":"exploit_available","old":"false","new":"true"}]}