Summary
CVE-2026-46670 is a critical, unauthenticated SQL injection vulnerability affecting YesWiki, an open-source wiki platform. The flaw resides in the Bazar form-import functionality (FormManager::create()) and allows any unauthenticated visitor to a default YesWiki install to inject arbitrary SQL and extract the entire database, including user password hashes. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause:
FormManager::create()performs unquoted concatenation of thebn_id_natureparameter directly into an SQLINSERT VALUESstatement without sanitization. - Trigger condition: An attacker submits a crafted Bazar form-import request containing SQL expressions (e.g., using
ASCII/SUBSTRING/HEX(VERSION())) in place of the expected numeric value. - Attack vector: The injected SQL expression is evaluated by the database before being stored, and the resulting inserted ID value leaks query results as numeric data, enabling character-by-character data extraction (a form of error/inference-based blind SQLi).
- Access requirements: No authentication and no user interaction are required; the vulnerable functionality is reachable by any unauthenticated visitor on a default installation.
- Impact: Full compromise of the underlying database, including exposure of the
yeswiki_userstable (usernames, emails, and password hashes), enabling downstream account takeover and further compromise.
Affected software
- YesWiki versions prior to 4.6.4, including confirmed vulnerable releases 4.6.1 and 4.6.2 (and the corresponding development branch commit).
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade YesWiki to version 4.6.4 or later, which patches the vulnerable SQL construction in
FormManager::create(). - If immediate patching is not possible: Restrict or disable public access to the Bazar form-import functionality, place a web application firewall in front of the instance to filter anomalous numeric/SQL-expression input in form submissions, and monitor database logs for suspicious query patterns.
- Following the upgrade, rotate credentials for all YesWiki user accounts, particularly administrative accounts, as password hashes may have already been exposed.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Named response header (
Link):YesWiki- - Raw response body:
yeswiki.net

