CVE-2026-861386.9Medium—6.9MediumIn libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.xmlsoft libxml219 MIN AGO
CVE-2026-861372.9Low—2.9LowIn libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.xmlsoft libxml221 MIN AGO
CVE-2026-527779.4Critical—9.4CriticalYesWiki: Authenticated PHP Object Injection in BazarImportAction via unserializeyeswiki yeswiki4 HR AGO
CVE-2026-527758.8High—8.8HighYesWiki Authenticated SQL Injection in ReactionManageryeswiki yeswiki4 HR AGO
CVE-2026-527746.1Medium—6.1MediumReflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWikiyeswiki yeswiki4 HR AGO
CVE-2026-527736.1Medium—6.1MediumReflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWikiyeswiki yeswiki4 HR AGO
CVE-2026-527725.5Medium—5.5MediumYesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and label-body contexts — stored XSS in form renders (sibling class of commit `e6b66aa`)yeswiki yeswiki4 HR AGO
CVE-2026-527718.3High—8.3HighYesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)yeswiki yeswiki4 HR AGO
CVE-2026-527707.5High—7.5HighImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswikiyeswiki yeswiki4 HR AGO
CVE-2026-527698.3High—8.3HighYesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`yeswiki yeswiki5 HR AGO
CVE-2026-527678.2High—8.2HighYesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`yeswiki yeswiki5 HR AGO
CVE-2026-527669.1Critical—9.1CriticalYesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` actionyeswiki yeswiki5 HR AGO
CVE-2026-527636.5Medium—6.5MediumYesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB readyeswiki yeswiki5 HR AGO
CVE-2026-527627.1High—7.1HighYesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templatesyeswiki yeswiki5 HR AGO
CVE-2026-861005.3Medium—5.3MediumCamaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URLowen2345 camaleoncms5 HR AGO