search
YesWiki
Trends
- 1High-severity SQL injection flaw found in YesWiki●🟠 CVE-2026-104460 - High (7.5) YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}
A high-severity vulnerability, tracked as CVE-2026-104460 with a score of 7.5, has been identified in YesWiki versions before 4.6.7. The blind SQL injection flaw sits in the newtextsearch action, where Bazar list option ids are concatenated into SQL REGEXP and LIKE clauses without escaping. Anonymous attackers can exploit it remotely, and users are being urged to update.
- 2YesWiki security flaw lets attackers hit admin API routes●🟠 CVE-2026-104467 - High (8.1) YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuth
A high-severity vulnerability, CVE-2026-104467, has been disclosed in YesWiki, a French open-source wiki software. Versions before 4.6.7 contain an authorization bypass in the ApiService::isAuthorized() function, allowing unauthenticated attackers to call admin-only API routes when public API mode is enabled. Administrators are urged to update to 4.6.7.