Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Tikiwiki Cms\/groupware MEDIUM 5.4
CVE-2021-36550

TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability a…

No fix yet
Fix from $1,600 2021-10-28
Tikiwiki Cms\/groupware MEDIUM 5.4
CVE-2021-36551

TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows att…

No fix yet
Fix from $1,600 2021-10-28
Tikiwiki Cms\/groupware HIGH 8.8
CVE-2020-29254

TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site req…

No fix yet
Fix from $1,950 2020-12-11
Tikiwiki Cms\/groupware CRITICAL 9.8
CVE-2010-4239EPSS 13%

Tiki Wiki CMS Groupware 5.2 has Local File Inclusion

No fix yet
Fix from $2,300 2019-10-28
Tikiwiki Cms\/groupware HIGH 8.8
CVE-2010-4241

Tiki Wiki CMS Groupware 5.2 has CSRF

No fix yet
Fix from $1,950 2019-10-28
Tikiwiki Cms\/groupware MEDIUM 6.1
CVE-2010-4240

Tiki Wiki CMS Groupware 5.2 has XSS

No fix yet
Fix from $1,600 2019-10-28
Tikiwiki Cms\/groupware MEDIUM 5.4
CVE-2019-15314

tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php…

No fix yet
Fix from $1,600 2019-08-22
Tiki HIGH 8.8
CVE-2018-7304

Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the vi…

No fix yet
Fix from $1,950 2018-02-21
Tiki MEDIUM 5.4
CVE-2018-7302

Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.

No fix yet
Fix from $1,600 2018-02-21
Tikiwiki Cms\/groupware MEDIUM 5.4
CVE-2018-7303

The Calendar component in Tiki 17.1 allows HTML injection.

No fix yet
Fix from $1,600 2018-02-21
Tikiwiki Cms\/groupware MEDIUM 6.1
CVE-2016-9889

Some forms with the parameter geo_zoomlevel_to_found_location in Tiki Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 LTS, and 16.x before 16.1 don'…

Mitigation only
Fix from $1,600 2016-12-23
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2013-4715

SQL injection vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remot…

Mitigation only
Fix from $1,950 2013-11-06
Tikiwiki Cms\/groupware MEDIUM 5.8
CVE-2012-5321EPSS 14%

tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attack…

No fix yet
Fix from $1,600 2012-10-08
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2010-1136

The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent lo…

Mitigation only
Fix from $1,950 2010-03-27
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2007-5423EPSS 77%

tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are proc…

No fix yet
Fix from $1,950 2007-10-12
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2006-6457

tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and p…

Mitigation only
Fix from $1,600 2006-12-11
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2006-5702EPSS 53%

Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-lis…

No fix yet
Fix from $1,600 2006-11-04
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2006-4734

Multiple SQL injection vulnerabilities in tiki-g-admin_processes.php in Tikiwiki 1.9.4 allow remote attackers to execute arbitrary SQL commands via t…

No fix yet
Fix from $1,950 2006-09-13
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2006-4602EPSS 44%

Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a f…

No fix yet
Fix from $1,950 2006-09-07
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2005-3529

tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topics_sort_mode pa…

No fix yet
Fix from $1,600 2005-11-20