Vulnerability Details CVE-2018-7290
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.1%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2018-7290
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.0
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.1
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.10
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.11
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.12
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.2
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.3
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.4
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.5
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.6
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.7
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.8
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:12.9
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:15.0
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:15.1
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:15.2
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:15.3
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:15.4
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:15.5
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:17.0
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:17.1
-
cpe:2.3:a:tiki:tikiwiki_cms/groupware:18.0