Tiki
73 known vulnerabilities
Top Products
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in
A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and ea
Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web scr
Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web
Tiki Wiki CMS Groupware 5.2 has CSRF
Tiki Wiki CMS Groupware 5.2 has XSS
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history p
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain
Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/pars
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE o
The Calendar component in Tiki 17.1 allows HTML injection.
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via
A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a c
Frequently Asked Questions
How many CVEs affect Tiki?
Tiki has 73 CVE records in our database, including 2 critical and 6 high severity vulnerabilities.
What are the most severe Tiki vulnerabilities?
Tiki has 2 critical severity (CVSS 9.0+) and 6 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Tiki vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Tiki products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Tiki Vulnerabilities
CyberStrike scans your infrastructure for Tiki vulnerabilities and provides real-time remediation guidance.
Get Started