CVE-2026-104460: YesWiki before 4.6.7 Unauthenticated Blind SQL Injection via newtextsearch
YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in actions/newtextsearch.php without escaping. Anonymous attackers can plant a malicious option id in an anonymously editable Bazar list and use search requests as a boolean oracle to read arbitrary database data, including admin password hashes from the yeswikiusers table.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to unauthenticated exploitation?
Deployments running a YesWiki version before 4.6.7 are exposed when an attacker can anonymously edit a Bazar list and can send requests that invoke the newtextsearch action. No authenticated account is required once those conditions are available.
What access does an attacker need to exploit the issue?
The attacker needs the ability to plant a malicious option ID in an anonymously editable Bazar list, then issue search requests and observe the boolean results. The vulnerability does not require prior authentication or user interaction.
What data could be obtained through exploitation?
An attacker can use the blind SQL injection as a boolean oracle to read arbitrary database data. The described impact includes administrator password hashes stored in the yeswiki_users table.