Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2024-46878
A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability all…
Tiki
27.1+
MEDIUM 5.4
CVE-2024-46879
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version 21.2. This vuln…
Tiki
21.11+
CRITICAL 9.8
CVE-2025-34111
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's defaul…
Tikiwiki Cms\/groupware
after 15.1
HIGH 7.2
CVE-2023-22851
Tiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.
Tiki
24.2+
HIGH 8.8
CVE-2023-22850
Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.
Tiki
24.1+
HIGH 8.8
CVE-2023-22853
Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.
Tiki
24.1+
MEDIUM 6.5
CVE-2023-22852
Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.
Tiki
after 25.0
MEDIUM 5.4
CVE-2021-36550
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability a…
Tikiwiki Cms\/groupware
No fix yet
MEDIUM 5.4
CVE-2021-36551
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows att…
Tikiwiki Cms\/groupware
No fix yet
HIGH 8.8
CVE-2020-29254
TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site req…
Tikiwiki Cms\/groupware
No fix yet
CRITICAL 9.8
CVE-2020-15906EPSS 27%
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
Tiki
21.2+
MEDIUM 6.1
CVE-2020-16131
Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.
Tiki
21.2+
MEDIUM 6.1
CVE-2020-8966
There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-…
Tikiwiki Cms\/groupware
after 20.0
MEDIUM 6.1
CVE-2013-6022
A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote maliciou…
Tikiwiki Cms\/groupware
after 11.0
HIGH 7.2
CVE-2011-4558
Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.
Tiki
after 8.2
MEDIUM 6.1
CVE-2011-4336EPSS 8%
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
Tikiwiki Cms\/groupware
after 7.0
MEDIUM 6.1
CVE-2011-4455
Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info…
Tiki
after 7.2
MEDIUM 6.1
CVE-2011-4454
Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path …
Tiki
after 7.2
CRITICAL 9.8
CVE-2010-4239EPSS 13%
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
Tikiwiki Cms\/groupware
No fix yet
HIGH 8.8
CVE-2010-4241
Tiki Wiki CMS Groupware 5.2 has CSRF
Tikiwiki Cms\/groupware
No fix yet
MEDIUM 6.1
CVE-2010-4240
Tiki Wiki CMS Groupware 5.2 has XSS
Tikiwiki Cms\/groupware
No fix yet
MEDIUM 5.4
CVE-2019-15314
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php…
Tikiwiki Cms\/groupware
No fix yet
HIGH 8.8
CVE-2018-20719
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.
Tikiwiki Cms\/groupware
17.2+
MEDIUM 5.4
CVE-2018-14849
Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.
Tikiwiki Cms\/groupware
12.14 / 15.7+
MEDIUM 5.4
CVE-2018-14850
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if a…
Tikiwiki Cms\/groupware
12.14 / 15.7+
MEDIUM 5.4
CVE-2018-7290
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
Tikiwiki Cms\/groupware
12.13 / 15.6+
HIGH 8.8
CVE-2018-7304
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the vi…
Tiki
No fix yet
MEDIUM 5.4
CVE-2018-7302
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
Tiki
No fix yet
MEDIUM 5.4
CVE-2018-7303
The Calendar component in Tiki 17.1 allows HTML injection.
Tikiwiki Cms\/groupware
No fix yet
MEDIUM 5.4
CVE-2018-7188
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a w…
Tikiwiki Cms\/groupware
18+