CVEPublished 2026-09-05Modified 2026-09-080 articles on news5 live referencesNVD data

CVE-2026-52762

Vulnerability data via NVD (ingested)

CVSS v3.1
EPSS percentile
37
Exploit Prediction Scoring System · top 63% of all CVEs
Description

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic template feature that can be escalated to confirmed Remote Code Execution (RCE). An authenticated administrator can place arbitrary Twig expressions into the Semantic template (Twig) field (bn_sem_template), and that content is later executed server-side when public semantic endpoints are requested. This issue has been patched in version 4.6.6.

Timeline
Published 2026-09-05
Modified 2026-09-08

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2026-52762 on GitHub.
We haven't classified any articles referencing CVE-2026-52762 yet. The external references above still apply.