CVEs (74)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tiki 1Tikiwiki Cms/groupware Jun 17, 2026 Jul 15, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to u...Show more |
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload u...Show more |
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted...Show more |
TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected...Show more |
There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the...Show more |
1Tiki 1Tikiwiki Cms/groupware Nov 21, 2024 Feb 12, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code. |
1Tiki 1Tikiwiki Cms/groupware Nov 21, 2024 Jan 15, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php. |
Tiki Wiki CMS Groupware 5.2 has CSRF |
1Tiki 1Tikiwiki Cms/groupware Nov 21, 2024 Oct 28, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Tiki Wiki CMS Groupware 5.2 has XSS |
1Tiki 1Tikiwiki Cms/groupware Nov 21, 2024 Oct 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Tiki Wiki CMS Groupware 5.2 has Local File Inclusion |
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI. |
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter. |
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a mo...Show more |
Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php. |
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1. |
The Calendar component in Tiki 17.1 allows HTML injection. |
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib...Show more |
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie. |
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an adm...Show more |
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if...Show more |