Vulnerability Description
YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. Attackers with page-write access (unauthenticated on default installs) can embed a nuagetag tag ending in a backslash to break quote parity and inject a UNION subquery, exfiltrating password hashes and arbitrary table data.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-p9rm-p6pp-8m8c
- https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-sql-injection-via-nuag
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-p9rm-p6pp-8m8c
FAQ
What is CVE-2026-104462?
CVE-2026-104462 is a vulnerability with a CVSS score of 7.5 (HIGH). YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. Attackers with page-write access (u...
How severe is CVE-2026-104462?
CVE-2026-104462 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-104462?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.