๐ต๏ธ RESEARCH & DEEP DIVES
-
YesWiki patches reflected XSS in Bazar widget id parameter (CVE-2026-52774)
YesWiki has fixed a reflected XSS vulnerability (CVE-2026-52774) in its Bazar widget handler in version 4.6.6.- Affects YesWiki, a PHP-based wiki system, in all versions prior to 4.6.6 when the Bazar extension is enabled.
- The Bazar widget handler reflects the id GET parameter into HTML attributes using only strip_tags(), which does not escape double quotes.
- An attacker can break out of the attribute value, inject an event handler such as onmouseover, and execute arbitrary JavaScript in the victim's browser.
- The flaw is reachable without authentication โ no login, page ownership, edit rights, or valid page tag is required; only the id parameter is needed.
- Tracked as CVE-2026-52774 (CWE-80), rated Medium 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N); fixed in YesWiki 4.6.6.
๐ Source: github.com ยท ๐ Coverage: cve.threatint.com ยท ๐ via CVE ThreatInt
-
ntop nDPI before 6.0 heap buffer overflow in ndpi_json_string_escape (CVE-2026-86098)
ntop nDPI versions before 6.0 contain a heap buffer overflow in the ndpi_json_string_escape function, tracked as CVE-2026-86098.- Affects ntop nDPI versions before 6.0, including the ndpi_serializer.c code at release 5.0
- The ndpi_json_string_escape function performs unbounded writes beyond caller-supplied buffer boundaries, causing heap corruption (CWE-787 out-of-bounds write)
- Attackers can trigger the overflow remotely with crafted network packet data such as TLS SNI, HTTP headers, or DNS names
- CVSS 4.0 score 8.3 (High) with network vector, high attack complexity, and high integrity/availability impact; no privileges or user interaction required
- Fixed in nDPI 6.0; finder credited to Tristan Madani, assigned by VulnCheck
๐ Source: cve.threatint.com ยท ๐ Coverage: vulncheck.com ยท ๐ via CVE ThreatInt
-
numbat - AI agent observability, (Fri, Sep 4th) โ SANS ISC
-
YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserial... โ CVE ThreatInt
-
YesWiki Authenticated SQL Injection in ReactionManagerYesWiki is a wiki syste... โ CVE ThreatInt
-
Reflected XSS via Unescaped Archived-Revision
timeParameter in `handlers/p... โ CVE ThreatInt -
YesWiki: Bazar form-field templates still apply
|raw('html')to `field.labe... โ CVE ThreatInt -
YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag... โ CVE ThreatInt
-
YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signatu... โ CVE ThreatInt
-
YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!open... โ CVE ThreatInt
-
YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}... โ CVE ThreatInt
-
YesWiki: SQL injection via the
recentchangesactionperiodargument leadi... โ CVE ThreatInt -
YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code ... โ CVE ThreatInt
-
Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URLCam... โ CVE ThreatInt
-
PX4 Autopilot through 1.17.0 Null Pointer Dereference via param selectPX4 Aut... โ CVE ThreatInt
-
PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task ... โ CVE ThreatInt
-
Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attrib... โ CVE ThreatInt
-
CRLF injection in Laravel's default email rule enables SMTP smuggling and spo... โ CVE ThreatInt
-
Twig: Sandbox method allowlist bypass via
MarkupsubclassTwig is a template... โ CVE ThreatInt -
Laravel CRLF Injection in Email Validation (CVE-2026-48019) โ thehackerwire.com (discovered)
-
IXON VPN Client CRLF Injection Allows Root/SYSTEM Command Execution โ thehackerwire.com (discovered)