Summary
CVE-2026-46670 is a critical, unauthenticated SQL injection vulnerability affecting YesWiki, an open-source wiki platform. The flaw resides in the Bazar form-import functionality (FormManager::create()) and allows any unauthenticated visitor to a default YesWiki install to inject arbitrary SQL and extract the entire database, including user password hashes. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause:
FormManager::create()performs unquoted concatenation of thebn_id_natureparameter directly into an SQLINSERT VALUESstatement without sanitization. - Trigger condition: An attacker submits a crafted Bazar form-import request containing SQL expressions (e.g., using
ASCII/SUBSTRING/HEX(VERSION())) in place of the expected numeric value. - Attack vector: The injected SQL expression is evaluated by the database before being stored, and the resulting inserted ID value leaks query results as numeric data, enabling character-by-character data extraction (a form of error/inference-based blind SQLi).
- Access requirements: No authentication and no user interaction are required; the vulnerable functionality is reachable by any unauthenticated visitor on a default installation.
- Impact: Full compromise of the underlying database, including exposure of the
yeswiki_userstable (usernames, emails, and password hashes), enabling downstream account takeover and further compromise.
Affected software
- YesWiki versions prior to 4.6.4, including confirmed vulnerable releases 4.6.1 and 4.6.2 (and the corresponding development branch commit).
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade YesWiki to version 4.6.4 or later, which patches the vulnerable SQL construction in
FormManager::create(). - If immediate patching is not possible: Restrict or disable public access to the Bazar form-import functionality, place a web application firewall in front of the instance to filter anomalous numeric/SQL-expression input in form submissions, and monitor database logs for suspicious query patterns.
- Following the upgrade, rotate credentials for all YesWiki user accounts, particularly administrative accounts, as password hashes may have already been exposed.

