Blind SQL Injection Vulnerability in YesWiki by YesWiki Team
CVE-2026-104460
8.7HIGH
What is CVE-2026-104460?
YesWiki versions prior to 4.6.7 suffer from a blind SQL injection vulnerability within the {{newtextsearch}} action. This flaw arises because option IDs used in SQL REGEXP/LIKE clauses are concatenated without adequate escaping in actions/newtextsearch.php. As a result, anonymous attackers can exploit this flaw by inserting a malicious option ID into an editable Bazar list, allowing them to perform search queries that function as a boolean oracle. This exploitation can lead to unauthorized access to sensitive database information, including the admin password hashes stored in the yeswiki_users table.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
