CRITICAL 9.1 CVE-2026-52766 Published 5 Sept 2026

YesWiki Unauthenticated Page Deletion

Worried this affects one of your servers?

YesWiki, a PHP-based wiki system, is affected by a serious security flaw.

Prior to version 4.6.6, the {{erasespamedcomments}} wiki action allows any user with write access to delete arbitrary pages, including admin and user-owned pages, without authorization.

This issue has been patched in version 4.6.6.

Reference: CVE-2026-52766 on NVD

← Back to Security News