Critical severity9.8NVD Advisory· Published Oct 22, 2020· Updated Jun 17, 2026
CVE-2020-15906
CVE-2020-15906
Description
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Tiki/Tikidescription
- Range: <21.2
Patches
Vulnerability mechanics
References
2- info.tiki.org/article473-Security-Releases-of-all-Tiki-versions-since-16-3nvdPatchVendor Advisory
- packetstormsecurity.com/files/159663/Tiki-Wiki-CMS-Groupware-21.1-Authentication-Bypass.htmlnvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.