Vulnerability index

Browse CVEs

70 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tikiwiki Cms\/groupware MEDIUM 6.1
CVE-2016-7394

tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.

Fix: after 15.2
Fix from $1,600 2018-02-06
Tikiwiki Cms\/groupware HIGH 8.0
CVE-2017-14924

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.…

Patch available
Fix from $1,950 2017-09-30
Tikiwiki Cms\/groupware HIGH 8.0
CVE-2017-14925

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.…

Patch available
Fix from $1,950 2017-09-30
Tikiwiki Cms\/groupware MEDIUM 6.1
CVE-2017-9145

TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.

Patch available
Fix from $1,600 2017-06-26
Tikiwiki Cms\/groupware MEDIUM 6.1
CVE-2017-9305

lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as de…

Patch available
Fix from $1,600 2017-05-31
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2016-10143

A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner U…

Patch available
Fix from $1,950 2017-01-20
Tikiwiki Cms\/groupware MEDIUM 6.1
CVE-2016-9889

Some forms with the parameter geo_zoomlevel_to_found_location in Tiki Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 LTS, and 16.x before 16.1 don'…

Mitigation only
Fix from $1,600 2016-12-23
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2013-4715

SQL injection vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remot…

Mitigation only
Fix from $1,950 2013-11-06
Tikiwiki Cms\/groupware MEDIUM 5.8
CVE-2012-5321EPSS 14%

tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attack…

No fix yet
Fix from $1,600 2012-10-08
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2012-3996

TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php…

Fix: after 8.2
Fix from $1,600 2012-07-12
Tikiwiki Cms\/groupware CRITICAL 9.8
CVE-2012-0911EPSS 63%

TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1)…

Fix: 6.7 / 8.4+
Fix from $2,300 2012-07-12
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2010-1133

Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecif…

Patch available
Fix from $1,950 2010-03-27
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2010-1134

SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitr…

Patch available
Fix from $1,950 2010-03-27
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2010-1135

The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain …

Patch available
Fix from $1,950 2010-03-27
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2010-1136

The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent lo…

Mitigation only
Fix from $1,950 2010-03-27
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2003-1574

TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Inte…

Patch available
Fix from $1,950 2009-08-24
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2008-5319

Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to tiki-error.php, a different issue than CVE-2008-365…

Fix: after 1.6.1
Fix from $1,600 2008-12-03
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2008-5318

Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to "size of user-provided input," a different issue th…

Fix: after 1.6.1
Fix from $1,600 2008-12-03
Tikiwiki Cms\/groupware HIGH 10.0
CVE-2008-3653

Multiple unspecified vulnerabilities in TikiWiki CMS/Groupware before 2.0 have unknown impact and attack vectors.

Fix: after 1.9.9
Fix from $1,950 2008-08-13
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2008-3654

Unspecified vulnerability in TikiWiki CMS/Groupware before 2.0 allows attackers to obtain "path and PHP configuration" via unknown vectors.

Fix: after 1.9.9
Fix from $1,600 2008-08-13
Tikiwiki Cms\/groupware HIGH 10.0
CVE-2007-6529

Multiple unspecified vulnerabilities in TikiWiki before 1.9.9 have unknown impact and attack vectors involving (1) tiki-edit_css.php, (2) tiki-list_g…

Fix: after 1.9.8
Fix from $1,950 2007-12-27
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2007-6528EPSS 9%

Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) …

Fix: after 1.9.8
Fix from $1,600 2007-12-27
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2007-5682

Incomplete blacklist vulnerability in tiki-graph_formula.php in TikiWiki before 1.9.8.2 allows remote attackers to execute arbitrary code by using va…

Fix: after 1.9.8
Fix from $1,950 2007-10-26
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2007-5684

Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an abs…

Fix: after 1.9.8.1
Fix from $1,950 2007-10-26
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2007-5423EPSS 77%

tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are proc…

No fix yet
Fix from $1,950 2007-10-12
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2006-6457

tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and p…

Mitigation only
Fix from $1,600 2006-12-11
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2006-6168

tiki-register.php in TikiWiki before 1.9.7 allows remote attackers to trigger "notification-spam" via certain vectors such as a comma-separated list …

Fix: after 1.9.6
Fix from $1,950 2006-11-29
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2006-5702EPSS 53%

Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-lis…

No fix yet
Fix from $1,600 2006-11-04
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2006-4734

Multiple SQL injection vulnerabilities in tiki-g-admin_processes.php in Tikiwiki 1.9.4 allow remote attackers to execute arbitrary SQL commands via t…

No fix yet
Fix from $1,950 2006-09-13
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2006-4602EPSS 44%

Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a f…

No fix yet
Fix from $1,950 2006-09-07