← Back

Tiki

tiki

91 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Tiki
tiki

CVEs (91)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tiki
1Tiki
Nov 21, 2024
Nov 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-admin_system.php, (2) tiki-pagehistory.php, (3) tiki-remov...Show more
Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-admin_system.php, (2) tiki-pagehistory.php, (3) tiki-removepage.php, or (4) tiki-rename_page.php.Show less
1Tiki
1Tiki
Nov 21, 2024
Nov 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-remind_password.php, (2) tiki-index.php, (3) tiki-logi...Show more
Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-remind_password.php, (2) tiki-index.php, (3) tiki-login_scr.php, or (4) tiki-index.Show less
1Tiki
1Tikiwiki Cms/groupware
Nov 21, 2024
Oct 28, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Tiki Wiki CMS Groupware 5.2 has CSRF
1Tiki
1Tikiwiki Cms/groupware
Nov 21, 2024
Oct 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Tiki Wiki CMS Groupware 5.2 has XSS
1Tiki
1Tikiwiki Cms/groupware
Nov 21, 2024
Oct 28, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
1Tiki
1Tikiwiki Cms/groupware
Jun 17, 2026
Aug 22, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.
1Tiki
1Tikiwiki Cms/groupware
Nov 21, 2024
Jan 15, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.
1Tiki
1Tikiwiki Cms/groupware
Nov 21, 2024
Aug 13, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a mo...Show more
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.Show less
1Tiki
1Tikiwiki Cms/groupware
Nov 21, 2024
Aug 13, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.
1Tiki
1Tikiwiki Cms/groupware
Jun 17, 2026
Mar 9, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
1Tiki
1Tiki
Jun 17, 2026
Feb 21, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd...Show more
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.Show less
1Tiki
1Tikiwiki Cms/groupware
Jun 17, 2026
Feb 21, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Calendar component in Tiki 17.1 allows HTML injection.
1Tiki
1Tiki
Jun 17, 2026
Feb 21, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
1Tiki
1Tikiwiki Cms/groupware
Jun 17, 2026
Feb 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib...Show more
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.Show less
1Tiki
1Tikiwiki Cms/groupware
Nov 21, 2024
Feb 6, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
1Tiki
1Tikiwiki Cms/groupware
May 13, 2026
Sep 30, 2017
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an adm...Show more
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.Show less
1Tiki
1Tikiwiki Cms/groupware
May 13, 2026
Sep 30, 2017
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if...Show more
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.Show less
1Tiki
1Tikiwiki Cms/groupware
May 13, 2026
Jun 26, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.
1Tiki
1Tikiwiki Cms/groupware
May 13, 2026
May 31, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.
1Tiki
1Tikiwiki Cms/groupware
May 13, 2026
Jan 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner URL field.