{"ok":true,"trend":{"id":749831,"platform":"mastodon","region":"global","key":"🟠 cve-2026-104460 - high (7.5) yeswiki before 4.6.7 contains a blind sql injection vulnerability in the {{newtextsearch}","title":"🟠 CVE-2026-104460 - High (7.5) YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}","url":"https://mastodon.social/@thehackerwire/117372038633571299","first_seen":"2026-10-02T15:37:29.884668Z","last_seen":"2026-10-02T15:37:29.884668Z","last_rank":11,"peak_rank":11,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.6896875,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A high-severity vulnerability, tracked as CVE-2026-104460 with a score of 7.5, has been identified in YesWiki versions before 4.6.7. The blind SQL injection flaw sits in the newtextsearch action, where Bazar list option ids are concatenated into SQL REGEXP and LIKE clauses without escaping. Anonymous attackers can exploit it remotely, and users are being urged to update.","why":"A newly disclosed high-severity vulnerability with a working exploitation path prompts admins to patch urgently.","tone":"neutral","entities":["YesWiki","CVE-2026-104460"],"summarized_at":"2026-10-02T15:38:19.227328Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1355},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"High-severity SQL injection flaw found in YesWiki","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-02T15:37:29.884668Z","rank":11,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@thehackerwire/117372038633571299","author":"thehackerwire","title":null,"snippet":"🟠 CVE-2026-104460 - High (7.5) YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in actions/newtextsearch.php without escaping. Anonymous attackers can…","posted_at":"2026-10-02T15:32:59.348000Z","likes":0}],"elsewhere":[],"window":"7d"}}