chiprook
← Security
SecurityOctober 3, 2026, 20:32

Nine YesWiki vulnerabilities found, including CVSS 8.6 SQL injection

Nine vulnerabilities were disclosed in YesWiki on October 2, 2026. The lead flaw, CVE-2026-104457 (CVSS 8.6), is an unauthenticated SQL injection in the Bazar filtertags action that lets attackers read the entire database, including administrator password hashes, via a UNION query. The cluster also includes three SSRF flaws, blind and second-order SQL injections, CSRF and unauthenticated page overwrite.

Nine YesWiki vulnerabilities found, including CVSS 8.6 SQL injection
#YesWiki
Read next
Security

CVE-2026-67401: cPanel EmailTrack SQL Injection Leads to Root Takeover

Security

CVE-2026-9586: SQL injection in Sangoma Switchvox rated 9.8

Security

Roundcube SQL injection CVE-2026-48842 exploited in the wild

Security

CVE-2026-75682 in Adobe Connect: SQL injection rated 9.9 leads to code execution