CVE-2026-52762
moderateStored Twig SSTI to RCE in YesWiki Bazar semantic templates
YesWiki Bazar prior to version 4.6.6 contains a stored server-side template injection (CWE-1336) in its semantic template feature: arbitrary Twig expressions saved in the bn_sem_template field are executed server-side when public semantic endpoints are subsequently requested. An authenticated administrator (or anyone able to edit Bazar form definitions) plants the payload, after which the injected Twig code runs in the server context on unauthenticated requests to those endpoints. The vendor-advised escalation to remote code execution is confirmed, meaning an attacker can run arbitrary code on the server hosting the wiki. All YesWiki deployments running a version earlier than 4.6.6 are affected, with risk concentrated on instances using Bazar and its semantic template field. Exploitation status: no public proof-of-concept, no CISA KEV listing, and no known in-the-wild exploitation; EPSS gives a 0.4% probability of exploitation within 30 days.
What to do: Upgrade YesWiki to version 4.6.6 or later. Until patched, audit the bn_sem_template (Semantic template/Twig) field on Bazar forms for unexpected or recently modified Twig expressions, restrict form-editing (administrator) privileges, and limit or WAF-protect public semantic endpoints. Because a payload must be planted by an authenticated administrator before it fires on public endpoints, review admin accounts and recent form-definition changes for signs of tampering.
| YesWiki (Bazar semantic template feature) | all versions prior to 4.6.6 (fixed in 4.6.6) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic template feature that can be escalated to confirmed Remote Code Execution (RCE). An authenticated administrator can place arbitrary Twig expressions into the Semantic template (Twig) field (bn_sem_template), and that content is later executed server-side when public semantic endpoints are requested. This issue has been patched in version 4.6.6.
- Weakness
- CWE-1336
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.