- The NVD record for CVE-2026-104457 says YesWiki before 4.6.7 has an SQL injection flaw that unauthenticated attackers can use on default installs to read table data.
- The flaw sits in page markup that visitors can save, so the editing feature is part of the attack surface, not only the login page.
- Check whether YesWiki runs anywhere in your organisation, confirm it is on 4.6.7 or later, and review password reuse.
Some software flaws live in obscure code. This one lives in a feature built to make content easier to use. In YesWiki, a page can carry markup that filters and groups entries. According to the vulnerability record, that markup can be turned against the database underneath it.
The idea is simple. When a system builds database commands from text that visitors can write, the text stops being content. It becomes instructions. The flaw is tracked as CVE-2026-104457 and affects YesWiki before version 4.6.7.
What the record says
The entry comes from the NIST National Vulnerability Database (NVD), published October 2, 2026. It describes an SQL injection flaw in the Bazar filtertags action. Bazar is the part of YesWiki that handles structured entries, and filtertags filters them by tag.
The record says unauthenticated attackers on default installs can exploit it. They save filtertags markup in a page. From there they can read arbitrary table data, with password hashes given as the example.
The record does not say whether anyone has used the flaw in the wild. It also does not say how many YesWiki sites exist. Treat it as a patch-or-verify item, not a confirmed incident.
How the flaw works
Filtertags accepts attributes named filterN, where N is a number. Each one holds a tag to filter by. The code never cleans these values. It puts quotes around each one and drops the result into a database query, inside the list of tag values the query matches against.
That matters because of how MySQL reads quotes. Under its backslash escaping, a backslash makes the next character literal. An attacker ends a token with a trailing backslash. That backslash cancels the closing quote, and the quote count falls out of balance.
Everything after that point is read as part of the command rather than as a tag. The record says this lets an attacker add a five-column UNION subquery. A UNION joins the results of a second query onto the first. The attacker chooses that second query, so it can read table data the application can reach.
The standard defence is a parameterised query. The command and the data travel separately, so data is not read as a command. The record describes the opposite: a command assembled by pasting text together.
How the score was set
VulnCheck scored the flaw under two systems. The CVSS 3.1 vector records a network attack, low complexity, no privileges and no user interaction. Confidentiality impact is high. Integrity and availability impact are low.
That profile fits the mechanism. The attack mainly reads data, with limited ability to change or disrupt it. The record shows no NVD-assigned score alongside these.
The lesson: the editing feature is part of the attack surface
Security reviews often focus on login pages and admin panels. This flaw sits in content that can be saved by someone with no account, on a default install. The risky input is a page, not a password field.
That changes the question for any site built on a wiki or content tool. Do not only ask who can log in. Ask what visitors can save, and which parts of the product read that saved text.
The exposure also reaches past one site. Password hashes are only a starting point. If staff reuse passwords elsewhere, a leaked hash becomes a problem for other systems.
What leaders should ask their teams
Start with inventory. Does any team, agency or vendor run YesWiki? Small wikis can sit outside central IT lists.
Then ask for the version number. Anything before 4.6.7 is in scope for this CVE. The record lists the project's GitHub security advisory and VulnCheck's advisory as references, so teams can read both.
Ask a second question: has the default configuration been checked? The record says default installs are exposed. A team that never changed the defaults should not assume it is safe.
Last, ask what happens if hashes were read. Which accounts share passwords with other systems? Who would decide on a reset?
A page that anyone can save should not be trusted as a database command. This record shows what happens when it is.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: NIST NVD.





