VYPR

Tiki

by Tiki

Source repositories

CVEs (60)

  • CVE-2020-15906CriOct 22, 2020
    risk 0.66cvss 9.8epss 0.27

    tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

  • CVE-2025-34113HigJul 15, 2025
    risk 0.60cvss epss 0.02

    An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET parameter in `tiki-calendar.php`. When the calendar module is enabled and an authenticated user has permission to access it, an…

  • CVE-2025-32461CriApr 9, 2025
    risk 0.57cvss 9.9epss 0.01

    wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.

  • CVE-2023-22850HigJan 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.

  • CVE-2023-22853HigJan 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.

  • CVE-2020-29254HigDec 11, 2020
    risk 0.57cvss 8.8epss 0.01

    TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF…

  • CVE-2018-20719HigJan 15, 2019
    risk 0.57cvss 8.8epss 0.01

    In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.

  • CVE-2018-7304HigFeb 21, 2018
    risk 0.57cvss 8.8epss 0.01

    Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.

  • CVE-2017-14925HigSep 30, 2017
    risk 0.52cvss 8.0epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related…

  • CVE-2017-14924HigSep 30, 2017
    risk 0.52cvss 8.0epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element,…

  • CVE-2011-4558HigJan 27, 2020
    risk 0.50cvss 7.2epss 0.04

    Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.

  • CVE-2023-22851HigJan 14, 2023
    risk 0.47cvss 7.2epss 0.01

    Tiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.

  • CVE-2023-22852MedJan 14, 2023
    risk 0.42cvss 6.5epss 0.00

    Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.

  • CVE-2013-6022MedFeb 12, 2020
    risk 0.40cvss 6.1epss 0.01

    A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code.

  • CVE-2011-4455MedNov 20, 2019
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-admin_system.php, (2) tiki-pagehistory.php, (3) tiki-removepage.php, or (4) tiki-rename_page.php.

  • CVE-2011-4454MedNov 20, 2019
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-remind_password.php, (2) tiki-index.php, (3) tiki-login_scr.php, or (4) tiki-index.

  • CVE-2024-46879MedMar 23, 2026
    risk 0.35cvss 5.4epss 0.00

    A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version 21.2. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive…

  • CVE-2024-46878MedMar 23, 2026
    risk 0.35cvss 5.4epss 0.00

    A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or…

  • CVE-2021-36551MedOct 28, 2021
    risk 0.35cvss 5.4epss 0.00

    TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module.

  • CVE-2021-36550MedOct 28, 2021
    risk 0.35cvss 5.4epss 0.00

    TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Create category module.

Page 1 of 3