VYPR

Tikiwiki CMS\/groupware

by Tiki

Source repositories

CVEs (78)

  • CVE-2021-36551MedOct 28, 2021
    risk 0.35cvss 5.4epss 0.00

    TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module.

  • CVE-2021-36550MedOct 28, 2021
    risk 0.35cvss 5.4epss 0.00

    TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Create category module.

  • CVE-2019-15314MedAug 22, 2019
    risk 0.35cvss 5.4epss 0.01

    tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.

  • CVE-2018-14850MedAug 13, 2018
    risk 0.35cvss 5.4epss 0.01

    Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.

  • CVE-2018-14849MedAug 13, 2018
    risk 0.35cvss 5.4epss 0.01

    Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.

  • CVE-2018-7290MedMar 9, 2018
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.

  • CVE-2018-7303MedFeb 21, 2018
    risk 0.35cvss 5.4epss 0.01

    The Calendar component in Tiki 17.1 allows HTML injection.

  • CVE-2018-7188MedFeb 16, 2018
    risk 0.35cvss 5.4epss 0.01

    An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.

  • CVE-2024-51506MedOct 28, 2024
    risk 0.31cvss 4.8epss 0.00

    Tiki through 27.0 allows users who have certain permissions to insert a "Create a Wiki Pages" stored XSS payload in the description.

  • CVE-2007-5423Oct 12, 2007
    risk 0.09cvss epss 0.77

    tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function.

  • CVE-2005-1921Jul 5, 2005
    risk 0.09cvss epss 0.79

    Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7)…

  • CVE-2006-5702Nov 4, 2006
    risk 0.07cvss epss 0.53

    Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6)…

  • CVE-2006-4602Sep 7, 2006
    risk 0.06cvss epss 0.44

    Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory.

  • CVE-2012-5321Oct 8, 2012
    risk 0.04cvss epss 0.14

    tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."

  • CVE-2007-6528Dec 27, 2007
    risk 0.04cvss epss 0.09

    Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) and modified filename in the movie parameter.

  • CVE-2004-1926Apr 11, 2004
    risk 0.04cvss epss 0.07

    Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a…

  • CVE-2011-4551Oct 1, 2012
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.

  • CVE-2012-3996Jul 12, 2012
    risk 0.03cvss epss 0.05

    TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.

  • CVE-2009-1204Apr 1, 2009
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to (1) tiki-galleries.php, (2) tiki-list_file_gallery.php, (3) tiki-listpages.php, and (4)…

  • CVE-2007-5684Oct 26, 2007
    risk 0.03cvss epss 0.03

    Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an absolute pathname in (1) error_handler_file and (2) local_php parameters to (a) tiki-index.php, or (3) encoded "..%2F" sequences in…