YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a… (CVE-2026-104462)
YesWiki versions before 4.6.7 have an SQL injection vulnerability in the Bazar nuagetag action. This flaw allows attackers with page-write access, which is unauthenticated on default installs, to inject SQL code by exploiting unescaped input in the tags attribute. The vulnerability can be used to exfiltrate password hashes and arbitrary table data. The vulnerability has a high severity score of 7.5 CVSS 3.1.
AI Analysis
Technical Summary
The vulnerability in YesWiki prior to version 4.6.7 is an SQL injection in the Bazar nuagetag action. The issue arises because the tags attribute is concatenated directly into a raw SQL IN clause without proper escaping. Attackers who have page-write access can craft a nuagetag tag ending with a backslash to break quote parity and inject a UNION subquery. This allows them to extract sensitive data such as password hashes and other arbitrary table contents from the database. The vulnerability is unauthenticated on default installations, increasing its risk.
Potential Impact
Successful exploitation allows an attacker to perform SQL injection attacks that can exfiltrate sensitive data including password hashes and arbitrary database table data. This can lead to data disclosure without requiring authentication on default installs, posing a significant confidentiality risk.
Mitigation Recommendations
A fix is available in YesWiki version 4.6.7. Users should upgrade to version 4.6.7 or later to remediate this vulnerability. No other mitigation guidance is provided. Patch status is not explicitly confirmed in vendor advisories here, but the version numbering indicates the fix is in 4.6.7.
YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a… (CVE-2026-104462)
Description
YesWiki versions before 4.6.7 have an SQL injection vulnerability in the Bazar nuagetag action. This flaw allows attackers with page-write access, which is unauthenticated on default installs, to inject SQL code by exploiting unescaped input in the tags attribute. The vulnerability can be used to exfiltrate password hashes and arbitrary table data. The vulnerability has a high severity score of 7.5 CVSS 3.1.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in YesWiki prior to version 4.6.7 is an SQL injection in the Bazar nuagetag action. The issue arises because the tags attribute is concatenated directly into a raw SQL IN clause without proper escaping. Attackers who have page-write access can craft a nuagetag tag ending with a backslash to break quote parity and inject a UNION subquery. This allows them to extract sensitive data such as password hashes and other arbitrary table contents from the database. The vulnerability is unauthenticated on default installations, increasing its risk.
Potential Impact
Successful exploitation allows an attacker to perform SQL injection attacks that can exfiltrate sensitive data including password hashes and arbitrary database table data. This can lead to data disclosure without requiring authentication on default installs, posing a significant confidentiality risk.
Mitigation Recommendations
A fix is available in YesWiki version 4.6.7. Users should upgrade to version 4.6.7 or later to remediate this vulnerability. No other mitigation guidance is provided. Patch status is not explicitly confirmed in vendor advisories here, but the version numbering indicates the fix is in 4.6.7.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mvpf-2445-p988
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-104462"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6abfee88a43b0b3b89e54bd8
Added to database: 10/02/2026, 17:48:56 UTC
Last enriched: 10/02/2026, 17:57:13 UTC
Last updated: 10/02/2026, 22:06:09 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.