CVE-2026-52774 | YesWiki up to 4.6.5 Bazar Widget /HomePage/widget strip_tags ID cross site scripting

SecurityVulns

A vulnerability has been found in YesWiki up to 4.6.5 and classified as problematic. This impacts the function strip_tags of the file /HomePage/widget of the component Bazar Widget Handler. This manipulation of the argument ID causes cross site scripting.

The identification of this vulnerability is CVE-2026-52774. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More