DEV Community

threataft
threataft

Posted on Originally published at threataft.com

YesWiki 9 CVEs — CVSS 8.6 SQL Injection Can Dump Your Entire Database

Nine vulnerabilities hit YesWiki on October 2, 2026. The lead flaw is CVE-2026-104457 (CVSS 8.6) — unauthenticated SQL injection in the Bazar filtertags action. No login required. Attackers can read the entire database, including administrator password hashes, by injecting a UNION query through a crafted wiki page.

The cluster also includes three SSRF flaws (CVE-2026-104442, CVE-2026-104464, CVE-2026-104463) reaching internal hosts and cloud metadata endpoints, blind SQL injection (CVE-2026-104460), second-order SQL injection via the ACL service (CVE-2026-104456), CSRF enabling package deletion (CVE-2026-104447), and unauthenticated page overwrite (CVE-2026-104449).

All nine are fixed in YesWiki 4.6.7.

Full technical breakdown including root cause, attack chains, and mitigation checklist: https://threataft.com/articles/yeswiki-cluster-cve-2026-104442-104447-104456-104457-104449-104460-104464-104463-104458

Top comments (0)