Critical severity9.8GHSA Advisory· Published Aug 11, 2026· Updated Aug 13, 2026
CVE-2026-46670
CVE-2026-46670
Description
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (FormManager::create()) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an INSERT statement and read the full database, including yeswiki_users.password hashes. Version 4.6.4 fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
yeswiki/yeswikiPackagist | < 4.6.4 | 4.6.4 |
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.