Skip to content

Known CVE

YesWiki Archived Revision - Cross-Site Scripting

YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coerces malformed DATETIME strings, an attacker can append an XSS payload after a valid revision timestamp.

CVE-2026-52773

Medium2026CVSS 6.1CWE-79

cve2026 · yeswiki · xss

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website