Critical severity9.9NVD Advisory· Published Apr 9, 2025· Updated Apr 15, 2026
CVE-2025-32461
CVE-2025-32461
Description
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.
Patches
679d58f1a423e406bea4f6c37801ed912390c9ffb4ab21bd8be8dc1aa220ff3f36c1ac702Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
8- seclists.org/fulldisclosure/2025/Jul/11nvd
- gitlab.com/tikiwiki/tiki/-/commit/406bea4f6c379a23903ecfd55e538d90fd669ab0nvd
- gitlab.com/tikiwiki/tiki/-/commit/801ed912390c2aa6caf12b7b953e200f5d4bc0b1nvd
- gitlab.com/tikiwiki/tiki/-/commit/9ffb4ab21bd86837370666ecd6afd868f3d7877anvd
- gitlab.com/tikiwiki/tiki/-/commit/be8dc1aa220fbceb07a7a5dc36416243afccd358nvd
- gitlab.com/tikiwiki/tiki/-/commit/f3f36c1ac702479209acfcaec5789d2fd1f996bcnvd
- tiki.org/article517nvd
- tiki.org/article518nvd
News mentions
0No linked articles in our index yet.