Vulnerability index

Browse CVEs

70 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tiki MEDIUM 5.4
CVE-2024-46878

A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability all…

Fix: 27.1+
Fix from $1,600 2026-03-23
Tiki MEDIUM 5.4
CVE-2024-46879

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version 21.2. This vuln…

Fix: 21.11+
Fix from $1,600 2026-03-23
Tikiwiki Cms\/groupware CRITICAL 9.8
CVE-2025-34111

An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's defaul…

Fix: after 15.1
Fix from $2,300 2025-07-15
Tiki HIGH 7.2
CVE-2023-22851

Tiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.

Fix: 24.2+
Fix from $1,950 2023-01-14
Tiki HIGH 8.8
CVE-2023-22850

Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.

Fix: 24.1+
Fix from $1,950 2023-01-14
Tiki HIGH 8.8
CVE-2023-22853

Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.

Fix: 24.1+
Fix from $1,950 2023-01-14
Tiki MEDIUM 6.5
CVE-2023-22852

Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.

Fix: after 25.0
Fix from $1,600 2023-01-14
Tikiwiki Cms\/groupware MEDIUM 5.4
CVE-2021-36550

TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability a…

No fix yet
Fix from $1,600 2021-10-28
Tikiwiki Cms\/groupware MEDIUM 5.4
CVE-2021-36551

TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows att…

No fix yet
Fix from $1,600 2021-10-28
Tikiwiki Cms\/groupware HIGH 8.8
CVE-2020-29254

TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site req…

No fix yet
Fix from $1,950 2020-12-11
Tiki CRITICAL 9.8
CVE-2020-15906EPSS 27%

tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

Fix: 21.2+
Fix from $2,300 2020-10-22
Tiki MEDIUM 6.1
CVE-2020-16131

Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.

Fix: 21.2+
Fix from $1,600 2020-08-03
Tikiwiki Cms\/groupware MEDIUM 6.1
CVE-2020-8966

There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-…

Fix: after 20.0
Fix from $1,600 2020-04-01
Tikiwiki Cms\/groupware MEDIUM 6.1
CVE-2013-6022

A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote maliciou…

Fix: after 11.0
Fix from $1,600 2020-02-12
Tiki HIGH 7.2
CVE-2011-4558

Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.

Fix: after 8.2
Fix from $1,950 2020-01-27
Tikiwiki Cms\/groupware MEDIUM 6.1
CVE-2011-4336EPSS 8%

Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.

Fix: after 7.0
Fix from $1,600 2020-01-15
Tiki MEDIUM 6.1
CVE-2011-4455

Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info…

Fix: after 7.2
Fix from $1,600 2019-11-20
Tiki MEDIUM 6.1
CVE-2011-4454

Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path …

Fix: after 7.2
Fix from $1,600 2019-11-20
Tikiwiki Cms\/groupware CRITICAL 9.8
CVE-2010-4239EPSS 13%

Tiki Wiki CMS Groupware 5.2 has Local File Inclusion

No fix yet
Fix from $2,300 2019-10-28
Tikiwiki Cms\/groupware HIGH 8.8
CVE-2010-4241

Tiki Wiki CMS Groupware 5.2 has CSRF

No fix yet
Fix from $1,950 2019-10-28
Tikiwiki Cms\/groupware MEDIUM 6.1
CVE-2010-4240

Tiki Wiki CMS Groupware 5.2 has XSS

No fix yet
Fix from $1,600 2019-10-28
Tikiwiki Cms\/groupware MEDIUM 5.4
CVE-2019-15314

tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php…

No fix yet
Fix from $1,600 2019-08-22
Tikiwiki Cms\/groupware HIGH 8.8
CVE-2018-20719

In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.

Fix: 17.2+
Fix from $1,950 2019-01-15
Tikiwiki Cms\/groupware MEDIUM 5.4
CVE-2018-14849

Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.

Fix: 12.14 / 15.7+
Fix from $1,600 2018-08-13
Tikiwiki Cms\/groupware MEDIUM 5.4
CVE-2018-14850

Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if a…

Fix: 12.14 / 15.7+
Fix from $1,600 2018-08-13
Tikiwiki Cms\/groupware MEDIUM 5.4
CVE-2018-7290

Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.

Fix: 12.13 / 15.6+
Fix from $1,600 2018-03-09
Tiki HIGH 8.8
CVE-2018-7304

Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the vi…

No fix yet
Fix from $1,950 2018-02-21
Tiki MEDIUM 5.4
CVE-2018-7302

Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.

No fix yet
Fix from $1,600 2018-02-21
Tikiwiki Cms\/groupware MEDIUM 5.4
CVE-2018-7303

The Calendar component in Tiki 17.1 allows HTML injection.

No fix yet
Fix from $1,600 2018-02-21
Tikiwiki Cms\/groupware MEDIUM 5.4
CVE-2018-7188

An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a w…

Fix: 18+
Fix from $1,600 2018-02-16