Mmastodon TechnologyCybersecurity first seen 7 h ago, last 7 h ago, peak #9
YesWiki hit by nine vulnerabilities including SQL injection flaw
Original: 🚨 YesWiki 9 CVEs — CVE-2026-104457 (CVSS 8.6) unauthenticated SQL injection dumps admin password hashes. No login requir
Nine security vulnerabilities have been disclosed in YesWiki, a French open-source wiki platform. The most severe, CVE-2026-104457 with a CVSS score of 8.6, is an unauthenticated SQL injection that can dump administrator password hashes without any login. Other reported flaws include three SSRF issues, blind and second-order SQL injection, CSRF and page overwrite. Fixes are available in YesWiki 4.6.7, and users are urged to patch immediately.
Why now: Admins of YesWiki instances are being urged to patch urgently following the disclosure of exploitable unauthenticated attacks.
Evidence
- 🚨 YesWiki 9 CVEs — CVE-2026-104457 (CVSS 8.6) unauthenticated SQL injection dumps admin password hashes. No login required. Also: 3× SSRF (ActivityPub, Bazar sync, IPv6 bypass), blind SQLi, second-order SQLi, CSRF, page overwrite. Fixed in YesWiki 4.6.7. Patch now. 👉 https://… · threataft@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/864420