CVE-2026-52777
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.
- Published Sep 5, 2026
- CVSS 9.4 critical
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available