Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Tiki

73 known vulnerabilities

1
CRITICAL
6
HIGH
15
MEDIUM

Top Products

tikiwiki cms\/groupware 16 tiki 6
22 CVEs
5.4
CVE-2024-46879

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in

5.4
CVE-2024-46878

A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and ea

6.1
CVE-2011-4455

Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web scr

6.1
CVE-2011-4454

Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web

8.8
CVE-2010-4241

Tiki Wiki CMS Groupware 5.2 has CSRF

6.1
CVE-2010-4240

Tiki Wiki CMS Groupware 5.2 has XSS

9.8
CVE-2010-4239

Tiki Wiki CMS Groupware 5.2 has Local File Inclusion

5.4
CVE-2019-15314

tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting

8.8
CVE-2018-20719

In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history p

5.4
CVE-2018-14850

Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain

5.4
CVE-2018-14849

Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/pars

5.4
CVE-2018-7290

Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.

8.8
CVE-2018-7304

Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE o

5.4
CVE-2018-7303

The Calendar component in Tiki 17.1 allows HTML injection.

5.4
CVE-2018-7302

Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.

5.4
CVE-2018-7188

An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges

6.1
CVE-2016-7394

tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.

8.0
CVE-2017-14925

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.

8.0
CVE-2017-14924

Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.

6.1
CVE-2017-9145

TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to

6.1
CVE-2017-9305

lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via

7.5
CVE-2016-10143

A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a c

Frequently Asked Questions

How many CVEs affect Tiki?

Tiki has 73 CVE records in our database, including 2 critical and 6 high severity vulnerabilities.

What are the most severe Tiki vulnerabilities?

Tiki has 2 critical severity (CVSS 9.0+) and 6 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Tiki vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Tiki products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Tiki Vulnerabilities

CyberStrike scans your infrastructure for Tiki vulnerabilities and provides real-time remediation guidance.

Get Started