CVE-2026-41143 - YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()
CVE ID :CVE-2026-41143 Published : May 7, 2026, 6:16 a.m. | 39 minutes ago Description :YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerability in tools/bazar/services/EntryManager.php at line 704. The $data['id_fiche'] value
ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD
Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.
GET THE SUNDAY BRIEFING →RELATED · cyber
- [CYBER] Sam Altman tükürdüğünü yaladı
- [CYBER] My .NET Docker image was 900MB - here's how I fixed it (and what I got wrong with JWT)
- [CYBER] Researchers Spot Uptick in Use of Vercel for Phishing Campaigns
- [CYBER] Number of malware programs targeting Russian companies rises to 1,174 since start of year
- [CYBER] CVE-2026-4430 - Heap Buffer Overflow in AgileEngine
- [CYBER] CVE-2026-44406 - DLL Hijacking Vulnerability in ZTE Cloud PC Client uSmartview