Vulnerabilities
Vulnerable Software
Tiki:  >> Tikiwiki Cms/groupware  Security Vulnerabilities
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.
CVSS Score
8.8
EPSS Score
0.002
Published
2019-01-15
Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.
CVSS Score
5.4
EPSS Score
0.003
Published
2018-08-13
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.
CVSS Score
5.4
EPSS Score
0.005
Published
2018-08-13
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-03-09
The Calendar component in Tiki 17.1 allows HTML injection.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-02-21
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.
CVSS Score
5.4
EPSS Score
0.003
Published
2018-02-16
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-02-06
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.
CVSS Score
8.0
EPSS Score
0.002
Published
2017-09-30
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.
CVSS Score
8.0
EPSS Score
0.002
Published
2017-09-30
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-06-26


Contact Us

Shodan ® - All rights reserved