CVE-2026-52766: Yeswiki

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki's allow-by-default action ACL model, any user who has page write access, which is the default for everyone (default_write_acl='*') on a fresh install can permanently delete arbitrary wiki pages, including the front page, admin pages, and pages owned by other users. This issue has been patched in version 4.6.6.

Affected products

  • Yeswiki Yeswiki: before 4.6.6 (fixed in 4.6.6)

Published 2026-09-05. Last modified 2026-09-09.