CVE-2026-46670Disclosure

LOW

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

1.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-08-11)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-23: 1Mentions · 2026-08-11: 3PoC Mentioned / Linked · 2026-08-11: 1Technical Details · 2026-05-23: 1Technical Details · 2026-08-11: 305-2308-11
Signal classification2 categories
Disclosure
375.0%
PoC
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-231
Disclosure1
2026-08-113
Disclosure2PoC1
Full discourse4 posts
  • Aretiq.AI@AretiqAI
    PoC

    ARETIQ Daily Vulnerability Bulletin — August 11, 2026 🔴 CRITICAL: CVE-2026-48362 (adobe/coldfusion_2025) AAS 13.8 🔴 CRITICAL: CVE-2026-71362 (adobe/adobe_commerce) AAS 13.8 — PoC available 🔴 CRITICAL: CVE-2026-72785 (craftcms/cms) AAS 13.5 — PoC available 🔴 CRITICAL: CVE-2026-72920 (seaweedfs/seaweedfs) AAS 13.1 — PoC available 🔴 CRITICAL: CVE-2026-46670 (yeswiki/yeswiki) AAS 12.4 — PoC available + 4 more CRITICAL 111 vulnerabilities — CRITICAL: 9, HIGH: 102 Full bulletin: https://aretiq.ai/bulletins/2026-08-11/

    Post summary

    The bulletin announces a broad set of critical CVEs, noting that several have proof‑of‑concept code available, but provides no evidence of active exploitation, patch availability, or false‑positive claims.

    010951.0K
    232 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - YesWiki Unauthenticated SQL Injection (CVE-2026-46670) An unauthenticated SQL injection vulnerability exists in YesWiki's Bazar form-import functionality (FormManager::create()). Any unauthenticated visitor can inject arbitrary SQL into an INSERT statement, allowing them to read the full database, including all user credentials (yeswiki_users.password hashes). This critical flaw (CVSS 9.8) affects default installations and enables complete data exfiltration without any authentication. 👉Affected: YesWiki < 4.6.4

    Post summary

    The post announces a critical unauthenticated SQL injection vulnerability in YesWiki, detailing its impact, affected version, and CVSS score.

    00011133
    196 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-46670 YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any … https://www.cve.org/CVERecord?id=CVE-2026-46670

    Post summary

    The post announces an unauthenticated SQL injection vulnerability in YesWiki prior to version 4.6.4, providing technical details but no PoC, exploit, or evidence of active exploitation.

    00010881
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-46670 YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any … https://www.cve.org/CVERecord?id=CVE-2026-46670 ----- Traducción: CVE-2026-46670 Yes… http://infoflow.cloud`

    Post summary

    Text discloses CVE-2026-46670, detailing an unauthenticated SQL injection vulnerability in YesWiki prior to version 4.6.4 and links to the official CVE record.

    0000030
    97 followersView on X

Explore more