Vulnerabilities
Vulnerable Software
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of the web server. The vulnerable component does not enforce file type validation, allowing attackers to craft a POST request to upload executable PHP payloads through the ELFinder interface exposed at /vendor_extra/elfinder/.
CVSS Score
9.8
EPSS Score
0.635
Published
2025-07-15
There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a legitimate web page.
CVSS Score
6.5
EPSS Score
0.003
Published
2020-04-01
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.
CVSS Score
8.8
EPSS Score
0.002
Published
2019-01-15
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.
CVSS Score
5.4
EPSS Score
0.003
Published
2018-02-16
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-02-06
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-06-26


Contact Us

Shodan ® - All rights reserved