CVE-2026-104460
Deferred Deferred - Pending Action

Blind SQL Injection in YesWiki Prior to 4.6.7

Vulnerability report for CVE-2026-104460, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in actions/newtextsearch.php without escaping. Anonymous attackers can plant a malicious option id in an anonymously editable Bazar list and use search requests as a boolean oracle to read arbitrary database data, including admin password hashes from the yeswiki_users table.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a blind SQL injection vulnerability in YesWiki versions before 4.6.7. It occurs in the {{newtextsearch}} action where Bazar list option IDs are directly concatenated into SQL REGEXP/LIKE clauses without proper escaping. Attackers can exploit this by inserting a malicious option ID into an anonymously editable Bazar list and using search requests as a boolean oracle to extract arbitrary database data, including admin password hashes.

Detection Guidance

To detect this vulnerability, check if your YesWiki instance is running a version before 4.6.7. Inspect the actions/newtextsearch.php file for unsanitized Bazar list option IDs being concatenated into SQL REGEXP/LIKE clauses. Monitor database queries for suspicious patterns or unauthorized data access attempts.

Impact Analysis

An attacker could read sensitive data from your database, such as admin credentials stored as unsalted MD5 hashes. They can exfiltrate any data from accessible tables without needing authentication or user interaction. The attack requires no privileges and can be executed remotely over the network.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive personal data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. It may result in non-compliance, legal penalties, and reputational damage due to data breaches.

Mitigation Strategies

Immediately upgrade YesWiki to version 4.6.7 or later. Disable anonymous editing of Bazar lists if not required. Review database access logs for signs of exploitation. Apply input validation to sanitize all user-supplied data before database queries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104460. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart