CVE Tools

Tiki

19 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Tiki, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Tiki CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Tiki CVEs per month
MonthCVEs
2024-104
2024-110
2024-120
2025-010
2025-020
2025-030
2025-041
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-032
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical211%
  • High526%
  • Medium1263%

Latest CVEs

The 15 most recently published vulnerabilities affecting Tiki.

  1. CVE-2024-46879A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version 21.2. This vulnerability allows attackers to execute arbitrary ...5.4
  2. CVE-2024-46878A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability allows attackers to execute arbitrary JavaScript co...5.4
  3. CVE-2025-32461wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.9.9
  4. CVE-2024-51509Tiki through 27.0 allows users who have certain permissions to insert a "Modules" (aka tiki-admin_modules.php) stored XSS payload in the Name.4.8
  5. CVE-2024-51508Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Index.4.8
  6. CVE-2024-51507Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Name.4.8
  7. CVE-2024-51506Tiki through 27.0 allows users who have certain permissions to insert a "Create a Wiki Pages" stored XSS payload in the description.4.8
  8. CVE-2023-22853Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.8.8
  9. CVE-2023-22850Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.8.8
  10. CVE-2023-22852Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.6.5
  11. CVE-2023-22851Tiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.7.2
  12. CVE-2020-15906tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.9.8
  13. CVE-2020-16131Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.6.1
  14. CVE-2013-6022A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code.6.1
  15. CVE-2011-4558Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.7.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store