Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-104462

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Oct 02, 2026
Vendor unknown

Description

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. Attackers with page-write access (unauthenticated on default installs) can embed a nuagetag tag ending in a backslash to break quote parity and inject a UNION subquery, exfiltrating password hashes and arbitrary table data.

References