<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 21:31:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-365789</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-365789</link>
      <description>EUVD-2026-365789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-365789</guid>
    </item>
    <item>
      <title>fkie_cve-2026-52766</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52766</link>
      <description>&lt;p&gt;YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki&amp;#39;s allow-by-default action ACL model, any user who has page write access, which is the default for everyone (default_write_acl=&amp;#39;*&amp;#39;) on a fresh install can permanently delete arbitrary wiki pages, including the front page, admin pages, and pages owned by other users. This issue has been patched in version 4.6.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki&amp;#39;s allow-by-default action ACL model, any user who has page write access, which is the default for everyone (default_write_acl=&amp;#39;*&amp;#39;) on a fresh install can permanently delete arbitrary wiki pages, including the front page, admin pages, and pages owned by other users. This issue has been patched in version 4.6.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-52766</guid>
    </item>
    <item>
      <title>GHSA-6x7x-gcmf-7r8x — YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6x7x-gcmf-7r8x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: yeswiki/yeswiki&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `{{erasespamedcomments}}` wiki action (`actions/EraseSpamedCommentsAction.php`) accepts a `suppr[]` array from `POST` and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki&amp;#39;s allow-by-default action ACL model, any user who has page write access, which is the default for everyone (`default_write_acl=&amp;#39;*&amp;#39;`) on a fresh install can permanently delete arbitrary wiki pages, including the front page, admin pages, and pages owned by other users.&lt;/p&gt;
&lt;p&gt;The action&amp;#39;s `delete()` callee is `PageManager::deleteOrphaned()`, which despite its name does not check whether the target page is orphaned: it issues an unconditional `DELETE` against `pages`, `links`, `acls`, `triples`, `referrers`, and `tags` tables.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Three issues compose the vulnerability.&lt;/p&gt;
&lt;p&gt;1. `actions/EraseSpamedCommentsAction.php` performs no authorization check before processing `$_POST[&amp;#39;clean&amp;#39;]` / `$_POST[&amp;#39;suppr&amp;#39;][]` in `actions/EraseSpamedCommentsAction.php`:&lt;/p&gt;
&lt;p&gt;```php
   public function run()
   {
       $wiki = &amp;amp;$this-&amp;gt;wiki;
       ob_start();
       // ...
       elseif (isset($_POST[&amp;#39;clean&amp;#39;])) {              
           $deletedPages = &amp;#39;&amp;#39;;
           if (!empty($_POST[&amp;#39;suppr&amp;#39;])) {            
               foreach ($_POST[&amp;#39;suppr&amp;#39;] as $page) {
                   echo &amp;#39;Effacement de : &amp;#39; . $page . &amp;#34;&amp;lt;br /&amp;gt;\n&amp;#34;;
                   if ($wiki-&amp;gt;services-&amp;gt;get(PageController::class)-&amp;gt;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: yeswiki/yeswiki&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `{{erasespamedcomments}}` wiki action (`actions/EraseSpamedCommentsAction.php`) accepts a `suppr[]` array from `POST` and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki&amp;#39;s allow-by-default action ACL model, any user who has page write access, which is the default for everyone (`default_write_acl=&amp;#39;*&amp;#39;`) on a fresh install can permanently delete arbitrary wiki pages, including the front page, admin pages, and pages owned by other users.&lt;/p&gt;
&lt;p&gt;The action&amp;#39;s `delete()` callee is `PageManager::deleteOrphaned()`, which despite its name does not check whether the target page is orphaned: it issues an unconditional `DELETE` against `pages`, `links`, `acls`, `triples`, `referrers`, and `tags` tables.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Three issues compose the vulnerability.&lt;/p&gt;
&lt;p&gt;1. `actions/EraseSpamedCommentsAction.php` performs no authorization check before processing `$_POST[&amp;#39;clean&amp;#39;]` / `$_POST[&amp;#39;suppr&amp;#39;][]` in `actions/EraseSpamedCommentsAction.php`:&lt;/p&gt;
&lt;p&gt;```php
   public function run()
   {
       $wiki = &amp;amp;$this-&amp;gt;wiki;
       ob_start();
       // ...
       elseif (isset($_POST[&amp;#39;clean&amp;#39;])) {              
           $deletedPages = &amp;#39;&amp;#39;;
           if (!empty($_POST[&amp;#39;suppr&amp;#39;])) {            
               foreach ($_POST[&amp;#39;suppr&amp;#39;] as $page) {
                   echo &amp;#39;Effacement de : &amp;#39; . $page . &amp;#34;&amp;lt;br /&amp;gt;\n&amp;#34;;
                   if ($wiki-&amp;gt;services-&amp;gt;get(PageController::class)-&amp;gt;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6x7x-gcmf-7r8x</guid>
    </item>
  </channel>
</rss>
