CVE-2026-104460: YesWiki before 4.6.7 Unauthenticated Blind SQL Injection via newtextsearch

Published Oct 2, 2026
·
Updated

YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in actions/newtextsearch.php without escaping. Anonymous attackers can plant a malicious option id in an anonymously editable Bazar list and use search requests as a boolean oracle to read arbitrary database data, including admin password hashes from the yeswikiusers table.

Affected Software

1 affected component
YesWiki YesWiki<4.6.7

Event History

Oct 2, 2026
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to unauthenticated exploitation?

Deployments running a YesWiki version before 4.6.7 are exposed when an attacker can anonymously edit a Bazar list and can send requests that invoke the newtextsearch action. No authenticated account is required once those conditions are available.

2

What access does an attacker need to exploit the issue?

The attacker needs the ability to plant a malicious option ID in an anonymously editable Bazar list, then issue search requests and observe the boolean results. The vulnerability does not require prior authentication or user interaction.

3

What data could be obtained through exploitation?

An attacker can use the blind SQL injection as a boolean oracle to read arbitrary database data. The described impact includes administrator password hashes stored in the yeswiki_users table.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203