<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T21:37:29.378397+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-365276</id>
    <title>EUVD-2026-365276</title>
    <updated>2026-10-09T21:37:29.437685+00:00</updated>
    <content>EUVD-2026-365276</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-365276"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52762</id>
    <title>fkie_cve-2026-52762</title>
    <updated>2026-10-09T21:37:29.437725+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic template feature that can be escalated to confirmed Remote Code Execution (RCE). An authenticated administrator can place arbitrary Twig expressions into the Semantic template (Twig) field (bn_sem_template), and that content is later executed server-side when public semantic endpoints are requested. This issue has been patched in version 4.6.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-52762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-65p8-9433-jpcp</id>
    <title>GHSA-65p8-9433-jpcp — YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates</title>
    <updated>2026-10-09T21:37:29.437760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: yeswiki/yeswiki</p>
<p>### Summary
YesWiki Bazar contains a stored Server-Side Template Injection (`SSTI`) vulnerability in the semantic template feature that can be escalated to confirmed Remote Code Execution (`RCE`). An authenticated administrator can place arbitrary Twig expressions into the `Semantic template (Twig)` field (`bn_sem_template`), and that content is later executed server-side when public semantic endpoints are requested.</p>
<p>This was first confirmed through a harmless proof payload where `{{ 7 * 7 }}` was rendered as `49` through the public JSON-LD endpoint. The finding was then further validated locally by storing a Twig payload that invoked a system-level callable, resulting in command execution and an interactive shell on the test machine.</p>
<p>Because the payload is stored in the form configuration and later triggered through a public endpoint, this issue is both persistent and remotely triggerable after an administrator plants the malicious template.</p>
<p>### Details
The vulnerable behavior is in the Bazar semantic rendering flow.</p>
<p>The administrator-editable fields:</p>
<p>- `bn_sem_template`
- `bn_sem_reverse_template`</p>
<p>allow Twig template content to be stored inside a form definition. That content is later rendered by the backend semantic transformer through `TemplateEngine::renderFromStringNoEscape()`, which passes the user-controlled string into Twig for execution.</p>
<p>Relevant sink:</p>
<p>```php
$json = $this-&gt;templateEngine-&gt;renderFromStringNoEscape($form['bn_sem_template'], $data);
```</p>
<p>The…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-65p8-9433-jpcp"/>
  </entry>
</feed>
