PT-2026-42810 · Yeswiki · Yeswiki

CVE-2026-46670

·

Published

2026-05-22

·

Updated

2026-08-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YesWiki versions prior to 4.6.4
Description An unauthenticated SQL injection exists in the Bazar form-import path within the FormManager::create() function. This flaw allows an unauthenticated visitor of a default installation to inject arbitrary SQL into an INSERT statement. An attacker can exploit this to read the entire database, including sensitive user credentials such as yeswiki users.password hashes. The issue is caused by the unquoted concatenation of the bn id nature variable into the INSERT VALUES list.
Recommendations Update YesWiki to version 4.6.4. As a temporary mitigation, restrict access to the Bazar form-import functionality until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46670
GHSA-JWVV-QR7Q-CV8J

Affected Products

Yeswiki