Nine YesWiki vulnerabilities found, including CVSS 8.6 SQL injection
Nine vulnerabilities were disclosed in YesWiki on October 2, 2026. The lead flaw, CVE-2026-104457 (CVSS 8.6), is an unauthenticated SQL injection in the Bazar filtertags action that lets attackers read the entire database, including administrator password hashes, via a UNION query. The cluster also includes three SSRF flaws, blind and second-order SQL injections, CSRF and unauthenticated page overwrite.
- CVE-2026-104457 (CVSS 8.6): unauthenticated SQL injection in Bazar filtertags
- Three SSRF flaws reach internal hosts and cloud metadata endpoints
- Also blind and second-order SQL injections, CSRF and page overwrite
- A UNION query dumps the whole DB, including admin password hashes
Read next
Security