Skip to content
Multiple SQL Injection Vulnerabilities Discovered in Yeswiki and Utmstack

Multiple SQL Injection Vulnerabilities Discovered in Yeswiki and Utmstack

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •Yeswiki and Utmstack are affected by SQL injection vulnerabilities.
  • •Both vulnerabilities allow unauthorized access through specific parameters.
  • •No active exploitation or proof-of-concept code has been reported.

Two separate SQL injection vulnerabilities have been identified in Yeswiki versions prior to 4.6.7 and Utmstack. The vulnerabilities, classified under CWE-89, allow attackers to manipulate SQL queries via specific parameters. Yeswiki's flaw is found in the 'filtertags' parameter, while Utmstack is affected through 'searchgroupsbyfilter'. Both vulnerabilities pose a risk of unauthorized data access and manipulation. There are no reports of or proof-of-concept code available for either vulnerability at this time. Users are advised to prioritize patching these vulnerabilities as part of their security measures. The vulnerabilities were disclosed on October 3, 2026, with no known exploits reported yet.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-03
Vulnerabilities disclosed
SQL injection vulnerabilities in Yeswiki and Utmstack were publicly disclosed, affecting multiple versions.
Vulncheck
2026-10-03
Advisory published for Utmstack
An advisory was released detailing the SQL injection vulnerability in Utmstack, urging users to patch.
Vulncheck

More articles in this cluster (2)

Common questions

Which versions of Yeswiki are affected?
Yeswiki versions prior to 4.6.7 are affected by the SQL injection vulnerability.
Is there a patch available?
Yes, users are advised to update to Yeswiki version 4.6.7 or later to mitigate the vulnerability.
What should organizations do to protect themselves?
Organizations should prioritize patching affected systems and monitor for any unusual activity related to these vulnerabilities.