Tikiwiki CMS\/groupware
by Tiki
Source repositories
CVEs (71)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2012-0911 | Cri | 0.72 | 9.8 | 0.63 | Jul 12, 2012 | TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b)… | ||
| CVE-2018-7304 | Hig | 0.57 | 8.8 | 0.01 | Feb 21, 2018 | Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation. | ||
| CVE-2017-14925 | Hig | 0.52 | 8.0 | 0.01 | Sep 30, 2017 | Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related… | ||
| CVE-2017-14924 | Hig | 0.52 | 8.0 | 0.01 | Sep 30, 2017 | Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element,… | ||
| CVE-2016-10143 | Hig | 0.49 | 7.5 | 0.02 | Jan 20, 2017 | A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner URL field. | ||
| CVE-2016-7394 | Med | 0.40 | 6.1 | 0.01 | Feb 6, 2018 | tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie. | ||
| CVE-2017-9145 | Med | 0.40 | 6.1 | 0.01 | Jun 26, 2017 | TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS. | ||
| CVE-2017-9305 | Med | 0.40 | 6.1 | 0.01 | May 31, 2017 | lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php. | ||
| CVE-2016-9889 | Med | 0.40 | 6.1 | 0.01 | Dec 23, 2016 | Some forms with the parameter geo_zoomlevel_to_found_location in Tiki Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 LTS, and 16.x before 16.1 don't have the input sanitized, related to tiki-setup.php and article_image.php. The impact is XSS. | ||
| CVE-2018-14850 | Med | 0.35 | 5.4 | 0.01 | Aug 13, 2018 | Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image. | ||
| CVE-2018-14849 | Med | 0.35 | 5.4 | 0.01 | Aug 13, 2018 | Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php. | ||
| CVE-2018-7290 | Med | 0.35 | 5.4 | 0.01 | Mar 9, 2018 | Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1. | ||
| CVE-2018-7303 | Med | 0.35 | 5.4 | 0.01 | Feb 21, 2018 | The Calendar component in Tiki 17.1 allows HTML injection. | ||
| CVE-2018-7188 | Med | 0.35 | 5.4 | 0.01 | Feb 16, 2018 | An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php. | ||
| CVE-2025-34111 | 0.10 | — | 0.02 | Jul 15, 2025 | An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of… | |||
| CVE-2007-5423 | 0.09 | — | 0.77 | Oct 12, 2007 | tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function. | |||
| CVE-2005-1921 | 0.09 | — | 0.79 | Jul 5, 2005 | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7)… | |||
| CVE-2006-5702 | 0.07 | — | 0.53 | Nov 4, 2006 | Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6)… | |||
| CVE-2006-4602 | 0.06 | — | 0.43 | Sep 7, 2006 | Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory. | |||
| CVE-2010-4239 | 0.04 | — | 0.13 | Oct 28, 2019 | Tiki Wiki CMS Groupware 5.2 has Local File Inclusion |
- risk 0.72cvss 9.8epss 0.63
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b)…
- risk 0.57cvss 8.8epss 0.01
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
- risk 0.52cvss 8.0epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related…
- risk 0.52cvss 8.0epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element,…
- risk 0.49cvss 7.5epss 0.02
A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner URL field.
- risk 0.40cvss 6.1epss 0.01
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
- risk 0.40cvss 6.1epss 0.01
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.
- risk 0.40cvss 6.1epss 0.01
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.
- risk 0.40cvss 6.1epss 0.01
Some forms with the parameter geo_zoomlevel_to_found_location in Tiki Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 LTS, and 16.x before 16.1 don't have the input sanitized, related to tiki-setup.php and article_image.php. The impact is XSS.
- risk 0.35cvss 5.4epss 0.01
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.
- risk 0.35cvss 5.4epss 0.01
Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
- risk 0.35cvss 5.4epss 0.01
The Calendar component in Tiki 17.1 allows HTML injection.
- risk 0.35cvss 5.4epss 0.01
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.
- CVE-2025-34111Jul 15, 2025risk 0.10cvss —epss 0.02
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of…
- CVE-2007-5423Oct 12, 2007risk 0.09cvss —epss 0.77
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function.
- CVE-2005-1921Jul 5, 2005risk 0.09cvss —epss 0.79
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7)…
- CVE-2006-5702Nov 4, 2006risk 0.07cvss —epss 0.53
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6)…
- CVE-2006-4602Sep 7, 2006risk 0.06cvss —epss 0.43
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory.
- CVE-2010-4239Oct 28, 2019risk 0.04cvss —epss 0.13
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
Page 1 of 4