MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 3 h ago, last 3 h ago, peak #11

High-severity SQL injection flaw found in YesWiki

Original: 🟠 CVE-2026-104460 - High (7.5) YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}

A high-severity vulnerability, tracked as CVE-2026-104460 with a score of 7.5, has been identified in YesWiki versions before 4.6.7. The blind SQL injection flaw sits in the newtextsearch action, where Bazar list option ids are concatenated into SQL REGEXP and LIKE clauses without escaping. Anonymous attackers can exploit it remotely, and users are being urged to update.

Why now: A newly disclosed high-severity vulnerability with a working exploitation path prompts admins to patch urgently.

YesWikiCVE-2026-104460

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/749831