SQL Injection Vulnerability in YesWiki Affects User Data Security
CVE-2026-104457
8.8HIGH
What is CVE-2026-104457?
YesWiki, prior to version 4.6.7, is exposed to a SQL injection flaw due to the mishandling of unescaped filterN attribute tokens in the Bazar filtertags action. This vulnerability allows unauthenticated attackers on default installations to manipulate filtertags markup by introducing a trailing backslash token, resulting in a break in quote parity under MySQL's backslash escaping. Consequently, attackers can exploit this flaw to inject complex UNION subqueries that may enable them to access sensitive information stored in the database, including user credentials and other confidential data.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
