Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jwvv-qr7q-cv8j | YesWiki: Unauthenticated SQL Injection |
Tue, 11 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue. | |
| Title | YesWiki: Unauthenticated SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-11T13:58:32.762Z
Reserved: 2026-05-15T21:46:51.547Z
Link: CVE-2026-46670
No data.
Status : Received
Published: 2026-08-11T14:17:13.863
Modified: 2026-08-11T14:17:13.863
Link: CVE-2026-46670
No data.
OpenCVE Enrichment
No data.
Github GHSA