VYPR
Vendor

Tiki

In Māori mythology, Tiki is the first man created by either Tūmatauenga or Tāne. He found the first woman, Marikoriko, in a pond; she seduced him, and he became the father of Hine-kau-ataata. By extension, a tiki is a large or small wooden, pounamu or other stone carving in humanoid form, although this is a somewhat archaic usage in the Māori language, where a tiki is usually a hei-tiki, a pendant worn around the neck. Hei-tiki are often considered taonga, especially if they are older and have been passed down throughout multiple generations.

Products
3
CVEs
94
Across products
144
Status
Private

Products

3

Recent CVEs

94
View all 94 CVEs →
  • CVE-2012-0911CriJul 12, 2012
    risk 0.72cvss 9.8epss 0.63

    TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b)…

  • CVE-2025-34111CriJul 15, 2025
    risk 0.67cvss 9.8epss 0.02

    An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of…

  • CVE-2020-15906CriOct 22, 2020
    risk 0.66cvss 9.8epss 0.27

    tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

  • CVE-2010-4239CriOct 28, 2019
    risk 0.65cvss 9.8epss 0.13

    Tiki Wiki CMS Groupware 5.2 has Local File Inclusion

  • CVE-2025-34113HigJul 15, 2025
    risk 0.60cvss epss 0.02

    An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET parameter in `tiki-calendar.php`. When the calendar module is enabled and an authenticated user has permission to access it, an…

  • CVE-2025-32461CriApr 9, 2025
    risk 0.57cvss 9.9epss 0.01

    wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.

  • CVE-2023-22850HigJan 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.

  • CVE-2023-22853HigJan 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.

  • CVE-2020-29254HigDec 11, 2020
    risk 0.57cvss 8.8epss 0.01

    TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF…

  • CVE-2010-4241HigOct 28, 2019
    risk 0.57cvss 8.8epss 0.01

    Tiki Wiki CMS Groupware 5.2 has CSRF

  • CVE-2018-20719HigJan 15, 2019
    risk 0.57cvss 8.8epss 0.01

    In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.

  • CVE-2018-7304HigFeb 21, 2018
    risk 0.57cvss 8.8epss 0.01

    Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.

  • CVE-2017-14925HigSep 30, 2017
    risk 0.52cvss 8.0epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related…

  • CVE-2017-14924HigSep 30, 2017
    risk 0.52cvss 8.0epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element,…

  • CVE-2011-4558HigJan 27, 2020
    risk 0.50cvss 7.2epss 0.04

    Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.

  • CVE-2016-10143HigJan 20, 2017
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner URL field.

  • CVE-2023-22851HigJan 14, 2023
    risk 0.47cvss 7.2epss 0.01

    Tiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.

  • CVE-2011-4336MedJan 15, 2020
    risk 0.43cvss 6.1epss 0.08

    Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.

  • CVE-2023-22852MedJan 14, 2023
    risk 0.42cvss 6.5epss 0.00

    Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.

  • CVE-2020-8966MedApr 1, 2020
    risk 0.42cvss 6.5epss 0.01

    There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a…