CVE-2026-52763 | YesWiki up to 4.6.5 recentchanges recentchanges.php getRecentlyChanged period sql injection
A vulnerability was found in YesWiki up to 4.6.5. It has been declared as critical. Affected by this issue is the function PageManager::getRecentlyChanged of the file actions/recentchanges.php of the component recentchanges. Executing a manipulation of the argument period can lead to sql injection.
This vulnerability is tracked as CVE-2026-52763. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More