Description
YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default installs can save filtertags markup in a page with a trailing-backslash token that breaks quote parity under MySQL backslash escaping. This lets them inject a five-column UNION subquery to read arbitrary table data such as password hashes.
Published: 2026-10-02
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Patch Immediately
AI Analysis

Impact

YesWiki versions before 4.6.7 allow unauthenticated attackers to inject SQL through the filtertags action. The vulnerability occurs because tokens from the filterN attribute are embedded directly inside a quotes‑wrapped IN clause without proper escaping, and a trailing backslash can toggle quote parity under MySQL’s backslash escaping. An attacker can then craft a UNION subquery that returns data from arbitrary tables, including password hashes, thereby compromising confidentiality and potentially enabling further exploitation.

Affected Systems

The affected product is YesWiki, all releases prior to 4.6.7. Attackers can target standard default installations that expose the Bazar filtertags functionality.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability, and while the EPSS score is not available, the known exploit potential is significant. The vulnerability is not currently listed in CISA KEV. Attackers need no authentication on a default install and can execute the injection via a crafted page that stores malicious markup.

Generated by OpenCVE AI on October 2, 2026 at 13:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply YesWiki version 4.6.7 or later to remove the vulnerable code
  • If upgrading is not immediately possible, disable the Bazar filtertags action or restrict its usage to trusted users
  • Configure MySQL to disallow backslash escaping or change the connection character set to prevent backslash handling

Generated by OpenCVE AI on October 2, 2026 at 13:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default installs can save filtertags markup in a page with a trailing-backslash token that breaks quote parity under MySQL backslash escaping. This lets them inject a five-column UNION subquery to read arbitrary table data such as password hashes.
Title YesWiki before 4.6.7 SQL Injection via filtertags filterN parameter
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-89
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:27.011Z

Reserved: 2026-10-02T00:53:58.504Z

Link: CVE-2026-104457

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:17.653

Modified: 2026-10-02T12:17:17.767

Link: CVE-2026-104457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:49:46Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')