tiki CVE Vulnerabilities & Metrics

Focus on tiki vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About tiki Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with tiki. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total tiki CVEs: 34
Earliest CVE date: 11 Apr 2004, 04:00 UTC
Latest CVE date: 14 Jan 2023, 02:15 UTC

Latest CVE reference: CVE-2023-22851

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical tiki CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.3

Max CVSS: 10.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 13
4.0-6.9 46
7.0-8.9 23
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS tiki CVEs

These are the five CVEs with the highest CVSS scores for tiki, sorted by severity first and recency.

All CVEs for tiki

CVE-2023-22851 tiki vulnerability CVSS: 0 14 Jan 2023, 02:15 UTC

Tiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.

CVE-2023-22850 tiki vulnerability CVSS: 0 14 Jan 2023, 02:15 UTC

Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.

CVE-2023-22853 tiki vulnerability CVSS: 0 14 Jan 2023, 01:15 UTC

Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.

CVE-2023-22852 tiki vulnerability CVSS: 0 14 Jan 2023, 01:15 UTC

Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.

CVE-2021-36551 tiki vulnerability CVSS: 3.5 28 Oct 2021, 20:15 UTC

TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module.

CVE-2021-36550 tiki vulnerability CVSS: 3.5 28 Oct 2021, 20:15 UTC

TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Create category module.

CVE-2020-29254 tiki vulnerability CVSS: 6.8 11 Dec 2020, 16:15 UTC

TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected system. An attacker could exploit this vulnerability by persuading a user of the interface to follow a maliciously crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These action include allowing attackers to submit their own code through an authenticated user resulting in local file Inclusion. If an authenticated user who is able to edit TikiWiki templates visits an malicious website, template code can be edited.

CVE-2020-15906 tiki vulnerability CVSS: 7.5 22 Oct 2020, 18:15 UTC

tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

CVE-2020-16131 tiki vulnerability CVSS: 4.3 03 Aug 2020, 17:15 UTC

Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.

CVE-2020-8966 tiki vulnerability CVSS: 4.3 01 Apr 2020, 21:15 UTC

There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a legitimate web page.

CVE-2013-6022 tiki vulnerability CVSS: 4.3 12 Feb 2020, 22:15 UTC

A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code.

CVE-2011-4558 tiki vulnerability CVSS: 6.0 27 Jan 2020, 15:15 UTC

Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.

CVE-2011-4336 tiki vulnerability CVSS: 4.3 15 Jan 2020, 14:15 UTC

Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.

CVE-2011-4455 tiki vulnerability CVSS: 4.3 20 Nov 2019, 19:15 UTC

Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-admin_system.php, (2) tiki-pagehistory.php, (3) tiki-removepage.php, or (4) tiki-rename_page.php.

CVE-2011-4454 tiki vulnerability CVSS: 4.3 20 Nov 2019, 19:15 UTC

Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-remind_password.php, (2) tiki-index.php, (3) tiki-login_scr.php, or (4) tiki-index.

CVE-2010-4241 tiki vulnerability CVSS: 6.8 28 Oct 2019, 15:15 UTC

Tiki Wiki CMS Groupware 5.2 has CSRF

CVE-2010-4240 tiki vulnerability CVSS: 4.3 28 Oct 2019, 15:15 UTC

Tiki Wiki CMS Groupware 5.2 has XSS

CVE-2010-4239 tiki vulnerability CVSS: 7.5 28 Oct 2019, 15:15 UTC

Tiki Wiki CMS Groupware 5.2 has Local File Inclusion

CVE-2019-15314 tiki vulnerability CVSS: 3.5 22 Aug 2019, 13:15 UTC

tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.

CVE-2018-20719 tiki vulnerability CVSS: 6.5 15 Jan 2019, 16:29 UTC

In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.

CVE-2018-14850 tiki vulnerability CVSS: 3.5 13 Aug 2018, 17:29 UTC

Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.

CVE-2018-14849 tiki vulnerability CVSS: 3.5 13 Aug 2018, 17:29 UTC

Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.

CVE-2018-7290 tiki vulnerability CVSS: 3.5 09 Mar 2018, 20:29 UTC

Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.

CVE-2018-7304 tiki vulnerability CVSS: 6.5 21 Feb 2018, 20:29 UTC

Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.

CVE-2018-7303 tiki vulnerability CVSS: 3.5 21 Feb 2018, 20:29 UTC

The Calendar component in Tiki 17.1 allows HTML injection.

CVE-2018-7302 tiki vulnerability CVSS: 3.5 21 Feb 2018, 20:29 UTC

Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.

CVE-2018-7188 tiki vulnerability CVSS: 3.5 16 Feb 2018, 18:29 UTC

An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.

CVE-2016-7394 tiki vulnerability CVSS: 4.3 06 Feb 2018, 16:29 UTC

tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.

CVE-2017-14925 tiki vulnerability CVSS: 6.0 30 Sep 2017, 01:29 UTC

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.

CVE-2017-14924 tiki vulnerability CVSS: 6.0 30 Sep 2017, 01:29 UTC

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.

CVE-2017-9145 tiki vulnerability CVSS: 4.3 26 Jun 2017, 13:29 UTC

TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.

CVE-2017-9305 tiki vulnerability CVSS: 4.3 31 May 2017, 04:29 UTC

lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.

CVE-2016-10143 tiki vulnerability CVSS: 5.0 20 Jan 2017, 08:59 UTC

A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner URL field.

CVE-2016-9889 tiki vulnerability CVSS: 4.3 23 Dec 2016, 05:59 UTC

Some forms with the parameter geo_zoomlevel_to_found_location in Tiki Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 LTS, and 16.x before 16.1 don't have the input sanitized, related to tiki-setup.php and article_image.php. The impact is XSS.

CVE-2013-4715 tiki vulnerability CVSS: 7.5 06 Nov 2013, 15:55 UTC

SQL injection vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2013-4714 tiki vulnerability CVSS: 4.3 06 Nov 2013, 15:55 UTC

Cross-site scripting (XSS) vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-5321 tiki vulnerability CVSS: 5.8 08 Oct 2012, 18:55 UTC

tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."

CVE-2011-4551 tiki vulnerability CVSS: 4.3 01 Oct 2012, 00:55 UTC

Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.

CVE-2012-3996 tiki vulnerability CVSS: 5.0 12 Jul 2012, 19:55 UTC

TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.

CVE-2012-0911 tiki vulnerability CVSS: 7.5 12 Jul 2012, 19:55 UTC

TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b) tiki-print_pages.php; or (4) sendpages, (5) sendstructures, or (6) sendarticles parameter to tiki-send_objects.php, which is not properly handled when processed by the unserialize function.

CVE-2010-1136 tiki vulnerability CVSS: 7.5 27 Mar 2010, 19:07 UTC

The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.

CVE-2010-1135 tiki vulnerability CVSS: 7.5 27 Mar 2010, 19:07 UTC

The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.

CVE-2010-1134 tiki vulnerability CVSS: 7.5 27 Mar 2010, 19:07 UTC

SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable.

CVE-2010-1133 tiki vulnerability CVSS: 7.5 27 Mar 2010, 19:07 UTC

Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) tiki-searchindex.php and (2) tiki-searchresults.php.

CVE-2003-1574 tiki vulnerability CVSS: 7.5 24 Aug 2009, 10:30 UTC

TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Internet Explorer "Remember Me" feature. NOTE: some of these details are obtained from third party information.

CVE-2009-1204 tiki vulnerability CVSS: 4.3 01 Apr 2009, 01:30 UTC

Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to (1) tiki-galleries.php, (2) tiki-list_file_gallery.php, (3) tiki-listpages.php, and (4) tiki-orphan_pages.php.

CVE-2008-5319 tiki vulnerability CVSS: 5.0 03 Dec 2008, 18:30 UTC

Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to tiki-error.php, a different issue than CVE-2008-3653.

CVE-2008-5318 tiki vulnerability CVSS: 5.0 03 Dec 2008, 18:30 UTC

Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to "size of user-provided input," a different issue than CVE-2008-3653.

CVE-2008-3653 tiki vulnerability CVSS: 10.0 13 Aug 2008, 01:41 UTC

Multiple unspecified vulnerabilities in TikiWiki CMS/Groupware before 2.0 have unknown impact and attack vectors.

CVE-2008-3654 tiki vulnerability CVSS: 5.0 13 Aug 2008, 01:41 UTC

Unspecified vulnerability in TikiWiki CMS/Groupware before 2.0 allows attackers to obtain "path and PHP configuration" via unknown vectors.

CVE-2008-1047 tiki vulnerability CVSS: 4.3 27 Feb 2008, 19:44 UTC

Cross-site scripting (XSS) vulnerability in tiki-edit_article.php in TikiWiki before 1.9.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2007-6529 tiki vulnerability CVSS: 10.0 27 Dec 2007, 22:46 UTC

Multiple unspecified vulnerabilities in TikiWiki before 1.9.9 have unknown impact and attack vectors involving (1) tiki-edit_css.php, (2) tiki-list_games.php, or (3) tiki-g-admin_shared_source.php.

CVE-2007-6528 tiki vulnerability CVSS: 5.0 27 Dec 2007, 22:46 UTC

Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) and modified filename in the movie parameter.

CVE-2007-6526 tiki vulnerability CVSS: 4.3 27 Dec 2007, 22:46 UTC

Cross-site scripting (XSS) vulnerability in tiki-special_chars.php in TikiWiki before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via the area_name parameter.

CVE-2007-5682 tiki vulnerability CVSS: 7.5 26 Oct 2007, 18:46 UTC

Incomplete blacklist vulnerability in tiki-graph_formula.php in TikiWiki before 1.9.8.2 allows remote attackers to execute arbitrary code by using variable functions and variable variables to write variables whose names match the whitelist, a different vulnerability than CVE-2007-5423.

CVE-2007-5684 tiki vulnerability CVSS: 7.5 26 Oct 2007, 18:46 UTC

Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an absolute pathname in (1) error_handler_file and (2) local_php parameters to (a) tiki-index.php, or (3) encoded "..%2F" sequences in the imp_language parameter to tiki-imexport_languages.php.

CVE-2007-5683 tiki vulnerability CVSS: 4.3 26 Oct 2007, 18:46 UTC

Multiple cross-site scripting (XSS) vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to the password reminder page (tiki-remind_password.php), (2) IMG tags in wiki pages, and (3) the local_php parameter to db/tiki-db.php.

CVE-2007-5423 tiki vulnerability CVSS: 7.5 12 Oct 2007, 23:17 UTC

tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function.

CVE-2007-4554 tiki vulnerability CVSS: 4.3 28 Aug 2007, 00:17 UTC

Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: this issue might be related to CVE-2006-2635.7.

CVE-2006-6457 tiki vulnerability CVSS: 5.0 11 Dec 2006, 17:28 UTC

tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.

CVE-2006-6168 tiki vulnerability CVSS: 7.5 29 Nov 2006, 02:28 UTC

tiki-register.php in TikiWiki before 1.9.7 allows remote attackers to trigger "notification-spam" via certain vectors such as a comma-separated list of addresses in the email field, related to lack of "a minimal check on email."

CVE-2006-6162 tiki vulnerability CVSS: 4.3 29 Nov 2006, 01:28 UTC

Cross-site scripting (XSS) vulnerability in tiki-edit_structures.php in TikiWiki 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the pageAlias parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2006-6163 tiki vulnerability CVSS: 4.3 29 Nov 2006, 01:28 UTC

Cross-site scripting (XSS) vulnerability in tiki-setup_base.php in TikiWiki before 1.9.7 allows remote attackers to inject arbitrary JavaScript via unspecified parameters.

CVE-2006-5702 tiki vulnerability CVSS: 5.0 04 Nov 2006, 01:07 UTC

Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6) tiki-directory_add_site.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-forums.php, (10) tiki-view_forum.php, (11) tiki-friends.php, (12) tiki-list_blogs.php, (13) tiki-list_faqs.php, (14) tiki-list_trackers.php, (15) tiki-list_users.php, (16) tiki-my_tiki.php, (17) tiki-notepad_list.php, (18) tiki-orphan_pages.php, (19) tiki-shoutbox.php, (20) tiki-usermenu.php, and (21) tiki-webmail_contacts.php, which reveal the information in certain database error messages.

CVE-2006-5703 tiki vulnerability CVSS: 4.3 04 Nov 2006, 01:07 UTC

Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML via a url parameter that evades filtering, as demonstrated by a parameter value containing malformed, nested SCRIPT elements.

CVE-2006-4734 tiki vulnerability CVSS: 7.5 13 Sep 2006, 22:07 UTC

Multiple SQL injection vulnerabilities in tiki-g-admin_processes.php in Tikiwiki 1.9.4 allow remote attackers to execute arbitrary SQL commands via the (1) pid and (2) where parameters.

CVE-2006-4602 tiki vulnerability CVSS: 7.5 07 Sep 2006, 00:04 UTC

Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory.

CVE-2006-4299 tiki vulnerability CVSS: 4.3 23 Aug 2006, 01:04 UTC

Cross-site scripting (XSS) vulnerability in tiki-searchindex.php in TikiWiki 1.9.4 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

CVE-2006-3048 tiki vulnerability CVSS: 7.5 16 Jun 2006, 10:02 UTC

SQL injection vulnerability in TikiWiki 1.9.3.2 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

CVE-2006-3047 tiki vulnerability CVSS: 4.3 16 Jun 2006, 10:02 UTC

Cross-site scripting (XSS) vulnerability in TikiWiki 1.9.3.2 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVE-2006-2635 tiki vulnerability CVSS: 4.3 30 May 2006, 10:02 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Tikiwiki (aka Tiki CMS/Groupware) 1.9.x allow remote attackers to inject arbitrary web script or HTML via malformed nested HTML tags such as "<scr<script>ipt>" in (1) offset and (2) days parameters in (a) tiki-lastchanges.php, the (3) find and (4) offset parameters in (b) tiki-orphan_pages.php, the (5) offset and (6) initial parameters in (c) tiki-listpages.php, and (7) an unspecified field in (d) tiki-remind_password.php; and allow remote authenticated users with admin privileges to inject arbitrary web script or HTML via (8) an unspecified field in a metatags action in (e) tiki-admin.php, the (9) offset parameter in (f) tiki-admin_rssmodules.php, the (10) offset and (11) max parameters in (g) tiki-syslog.php, the (12) numrows parameter in (h) tiki-adminusers.php, (13) an unspecified field in (i) tiki-adminusers.php, (14) an unspecified field in (j) tiki-admin_hotwords.php, unspecified fields in (15) "Assign new module" and (16) "Create new user module" in (k) tiki-admin_modules.php, (17) an unspecified field in "Add notification" in (l) tiki-admin_notifications.php, (18) the offset parameter in (m) tiki-admin_notifications.php, the (19) Name and (20) Dsn fields in (o) tiki-admin_dsn.php, the (21) offset parameter in (p) tiki-admin_content_templates.php, (22) an unspecified field in "Create new template" in (q) tiki-admin_content_templates.php, and the (23) offset parameter in (r) tiki-admin_chat.php.

CVE-2005-3529 tiki vulnerability CVSS: 5.0 20 Nov 2005, 22:03 UTC

tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topics_sort_mode parameter, possibly related to an SQL injection vulnerability.

CVE-2005-3528 tiki vulnerability CVSS: 4.3 20 Nov 2005, 22:03 UTC

Cross-site scripting (XSS) vulnerability in tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to inject arbitrary web script or HTML via the topics_offset parameter.

CVE-2005-1925 tiki vulnerability CVSS: 7.5 18 Nov 2005, 06:03 UTC

Multiple directory traversal vulnerabilities in Tikiwiki before 1.9.1 allow remote attackers to read arbitrary files and execute commands via (1) the suck_url parameter to tiki-editpage.php or (2) language parameter to tiki-user_preferences.php.

CVE-2005-3283 tiki vulnerability CVSS: 4.3 23 Oct 2005, 10:02 UTC

Cross-site scripting (XSS) vulnerability in TikiWiki before 1.9.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2005-1921 tiki vulnerability CVSS: 7.5 05 Jul 2005, 04:00 UTC

Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.

CVE-2005-0200 tiki vulnerability CVSS: 7.5 02 May 2005, 04:00 UTC

TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.

CVE-2004-1386 tiki vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200.

CVE-2004-1925 tiki vulnerability CVSS: 7.5 12 Apr 2004, 04:00 UTC

Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (1) tiki-usermenu.php, (2) tiki-list_file_gallery.php, (3) tiki-directory_ranking.php, (4) tiki-browse_categories.php, (5) tiki-index.php, (6) tiki-user_tasks.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-file_galleries.php, (10) tiki-list_faqs.php, (11) tiki-list_trackers.php, (12) tiki-list_blogs.php, or via the offset parameter in (13) tiki-usermenu.php, (14) tiki-browse_categories.php, (15) tiki-index.php, (16) tiki-user_tasks.php, (17) tiki-list_faqs.php, (18) tiki-list_trackers.php, or (19) tiki-list_blogs.php.

CVE-2004-1928 tiki vulnerability CVSS: 7.5 12 Apr 2004, 04:00 UTC

The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.

CVE-2004-1926 tiki vulnerability CVSS: 7.5 11 Apr 2004, 04:00 UTC

Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation.

CVE-2004-1923 tiki vulnerability CVSS: 5.0 11 Apr 2004, 04:00 UTC

Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-admin_include_directory.php, (4) tiki-directory_search.php, which reveal the web server path in an error message.

CVE-2004-1927 tiki vulnerability CVSS: 5.0 11 Apr 2004, 04:00 UTC

Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter.

CVE-2004-1924 tiki vulnerability CVSS: 4.3 11 Apr 2004, 04:00 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1) theme parameter to tiki-switch_theme.php, (2) find and priority parameters to messu-mailbox.php, (3) flag, priority, flagval, sort_mode, or find parameters to messu-read.php, (4) articleId parameter to tiki-read_article.php, (5) parentId parameter to tiki-browse_categories.php, (6) comments_threshold parameter to tiki-index.php (7) articleId parameter to tiki-print_article.php, (8) galleryId parameter to tiki-list_file_gallery.php, (9) galleryId parameter to tiki-upload_file.php, (10) faqId parameter to tiki-view_faq.php, (11) chartId parameter to tiki-view_chart.php, or (12) surveyId parameter to tiki-survey_stats_survey.php.