VYPR

Tiki

by Tiki

Source repositories

CVEs (60)

  • CVE-2019-15314MedAug 22, 2019
    risk 0.35cvss 5.4epss 0.01

    tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.

  • CVE-2018-7302MedFeb 21, 2018
    risk 0.35cvss 5.4epss 0.01

    Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.

  • CVE-2024-51509MedOct 28, 2024
    risk 0.31cvss 4.8epss 0.00

    Tiki through 27.0 allows users who have certain permissions to insert a "Modules" (aka tiki-admin_modules.php) stored XSS payload in the Name.

  • CVE-2024-51508MedOct 28, 2024
    risk 0.31cvss 4.8epss 0.00

    Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Index.

  • CVE-2024-51507MedOct 28, 2024
    risk 0.31cvss 4.8epss 0.00

    Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Name.

  • CVE-2024-51506MedOct 28, 2024
    risk 0.31cvss 4.8epss 0.00

    Tiki through 27.0 allows users who have certain permissions to insert a "Create a Wiki Pages" stored XSS payload in the description.

  • CVE-2007-5423Oct 12, 2007
    risk 0.09cvss epss 0.77

    tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function.

  • CVE-2006-5702Nov 4, 2006
    risk 0.07cvss epss 0.53

    Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6)…

  • CVE-2006-4602Sep 7, 2006
    risk 0.06cvss epss 0.44

    Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory.

  • CVE-2007-6528Dec 27, 2007
    risk 0.04cvss epss 0.09

    Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) and modified filename in the movie parameter.

  • CVE-2004-1926Apr 11, 2004
    risk 0.04cvss epss 0.07

    Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a…

  • CVE-2009-1204Apr 1, 2009
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to (1) tiki-galleries.php, (2) tiki-list_file_gallery.php, (3) tiki-listpages.php, and (4)…

  • CVE-2007-5684Oct 26, 2007
    risk 0.03cvss epss 0.03

    Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an absolute pathname in (1) error_handler_file and (2) local_php parameters to (a) tiki-index.php, or (3) encoded "..%2F" sequences in…

  • CVE-2006-5703Nov 4, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML via a url parameter that evades filtering, as demonstrated by a parameter value containing malformed, nested SCRIPT elements.

  • CVE-2004-1924Apr 11, 2004
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1) theme parameter to tiki-switch_theme.php, (2) find and priority parameters to messu-mailbox.php,…

  • CVE-2020-16131MedAug 3, 2020
    risk 0.00cvss 6.1epss 0.01

    Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.

  • CVE-2003-1574Aug 24, 2009
    risk 0.00cvss epss 0.02

    TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Internet Explorer "Remember Me" feature. NOTE: some of these details are obtained from third party information.

  • CVE-2008-5319Dec 3, 2008
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to tiki-error.php, a different issue than CVE-2008-3653.

  • CVE-2008-5318Dec 3, 2008
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to "size of user-provided input," a different issue than CVE-2008-3653.

  • CVE-2008-3654Aug 13, 2008
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in TikiWiki CMS/Groupware before 2.0 allows attackers to obtain "path and PHP configuration" via unknown vectors.