CRITICAL
9.1 CVE-2026-52766 Published 5 Sept 2026
YesWiki Unauthenticated Page Deletion
Worried this affects one of your servers?
YesWiki, a PHP-based wiki system, is affected by a serious security flaw.
Prior to version 4.6.6, the {{erasespamedcomments}} wiki action allows any user with write access to delete arbitrary pages, including admin and user-owned pages, without authorization.
This issue has been patched in version 4.6.6.
Reference: CVE-2026-52766 on NVD
← Back to Security News