HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-104457 — YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filter...

·Source: NIST NVD

Updated:

Executive Summary

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default installs can save filtertags markup in a page with a trailing-backslash token that breaks quote parity under MySQL backslash escaping. This lets them in

Analysis

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default installs can save filtertags markup in a page with a trailing-backslash token that breaks quote parity under MySQL backslash escaping. This lets them inject a five-column UNION subquery to read arbitrary table data such as password hashes. CVSS Score: 8.6. Published: 2026-10-02T12:17:17.653.

Indicators of Compromise (1)

CVE (1)
CVE-2026-104457
Source Attribution

Originally published by NIST NVD on Oct 2, 2026. Verified by: NIST.

Related Threats