Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2016-7394
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
Tikiwiki Cms\/groupware
after 15.2
HIGH 8.0
CVE-2017-14924
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.…
Tikiwiki Cms\/groupware
Patch available
HIGH 8.0
CVE-2017-14925
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.…
Tikiwiki Cms\/groupware
Patch available
MEDIUM 6.1
CVE-2017-9145
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.
Tikiwiki Cms\/groupware
Patch available
MEDIUM 6.1
CVE-2017-9305
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as de…
Tikiwiki Cms\/groupware
Patch available
HIGH 7.5
CVE-2016-10143
A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner U…
Tikiwiki Cms\/groupware
Patch available
MEDIUM 6.1
CVE-2016-9889
Some forms with the parameter geo_zoomlevel_to_found_location in Tiki Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 LTS, and 16.x before 16.1 don'…
Tikiwiki Cms\/groupware
Mitigation only
HIGH 7.5
CVE-2013-4715
SQL injection vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remot…
Tikiwiki Cms\/groupware
Mitigation only
MEDIUM 5.8
CVE-2012-5321EPSS 14%
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attack…
Tikiwiki Cms\/groupware
No fix yet
MEDIUM 5.0
CVE-2012-3996
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php…
Tikiwiki Cms\/groupware
after 8.2
CRITICAL 9.8
CVE-2012-0911EPSS 63%
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1)…
Tikiwiki Cms\/groupware
6.7 / 8.4+
HIGH 7.5
CVE-2010-1133
Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecif…
Tikiwiki Cms\/groupware
Patch available
HIGH 7.5
CVE-2010-1134
SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitr…
Tikiwiki Cms\/groupware
Patch available
HIGH 7.5
CVE-2010-1135
The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain …
Tikiwiki Cms\/groupware
Patch available
HIGH 7.5
CVE-2010-1136
The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent lo…
Tikiwiki Cms\/groupware
Mitigation only
HIGH 7.5
CVE-2003-1574
TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Inte…
Tikiwiki Cms\/groupware
Patch available
MEDIUM 5.0
CVE-2008-5319
Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to tiki-error.php, a different issue than CVE-2008-365…
Tikiwiki Cms\/groupware
after 1.6.1
MEDIUM 5.0
CVE-2008-5318
Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to "size of user-provided input," a different issue th…
Tikiwiki Cms\/groupware
after 1.6.1
HIGH 10.0
CVE-2008-3653
Multiple unspecified vulnerabilities in TikiWiki CMS/Groupware before 2.0 have unknown impact and attack vectors.
Tikiwiki Cms\/groupware
after 1.9.9
MEDIUM 5.0
CVE-2008-3654
Unspecified vulnerability in TikiWiki CMS/Groupware before 2.0 allows attackers to obtain "path and PHP configuration" via unknown vectors.
Tikiwiki Cms\/groupware
after 1.9.9
HIGH 10.0
CVE-2007-6529
Multiple unspecified vulnerabilities in TikiWiki before 1.9.9 have unknown impact and attack vectors involving (1) tiki-edit_css.php, (2) tiki-list_g…
Tikiwiki Cms\/groupware
after 1.9.8
MEDIUM 5.0
CVE-2007-6528EPSS 9%
Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) …
Tikiwiki Cms\/groupware
after 1.9.8
HIGH 7.5
CVE-2007-5682
Incomplete blacklist vulnerability in tiki-graph_formula.php in TikiWiki before 1.9.8.2 allows remote attackers to execute arbitrary code by using va…
Tikiwiki Cms\/groupware
after 1.9.8
HIGH 7.5
CVE-2007-5684
Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an abs…
Tikiwiki Cms\/groupware
after 1.9.8.1
HIGH 7.5
CVE-2007-5423EPSS 77%
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are proc…
Tikiwiki Cms\/groupware
No fix yet
MEDIUM 5.0
CVE-2006-6457
tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and p…
Tikiwiki Cms\/groupware
Mitigation only
HIGH 7.5
CVE-2006-6168
tiki-register.php in TikiWiki before 1.9.7 allows remote attackers to trigger "notification-spam" via certain vectors such as a comma-separated list …
Tikiwiki Cms\/groupware
after 1.9.6
MEDIUM 5.0
CVE-2006-5702EPSS 53%
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-lis…
Tikiwiki Cms\/groupware
No fix yet
HIGH 7.5
CVE-2006-4734
Multiple SQL injection vulnerabilities in tiki-g-admin_processes.php in Tikiwiki 1.9.4 allow remote attackers to execute arbitrary SQL commands via t…
Tikiwiki Cms\/groupware
No fix yet
HIGH 7.5
CVE-2006-4602EPSS 44%
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a f…
Tikiwiki Cms\/groupware
No fix yet