All vulnerabilities
89 / 89
Sort
7.5
CVE-2007-5423DEB
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via …
2007-01-01
EPSS76.7%
pct 99
9.8
CVE-2012-0911DEB
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitra…
2012-01-01Pre-auth
EPSS63.0%
pct 99
5.0
CVE-2006-5702DEB
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and pass…
2006-01-01
EPSS53.1%
pct 98
7.5
CVE-2006-4602DEB
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows …
2006-01-01
EPSS42.6%
pct 98
9.8
CVE-2020-15906DEB
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid lo…
2020-01-01Pre-auth
EPSS26.7%
pct 97
9.8
CVE-2010-4239DEB
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
2010-01-01Pre-auth
EPSS13.4%
pct 95
5.0
CVE-2007-6528DEB
Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote…
2007-01-01
EPSS9.3%
pct 94
5.8
CVE-2012-5321DEB
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary …
2012-01-01
EPSS7.7%
pct 93
6.1
CVE-2011-4336DEB
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
2011-01-01Pre-auth
EPSS7.7%
pct 93
5.0
CVE-2012-3996DEB
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path …
2012-01-01
EPSS4.6%
pct 90
4.3
CVE-2009-1204DEB
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote att…
2009-01-01
EPSS4.5%
pct 90
7.2
CVE-2011-4558DEB
Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted inp…
2011-01-01
EPSS4.3%
pct 89
4.3
CVE-2006-2635DEB
Multiple cross-site scripting (XSS) vulnerabilities in Tikiwiki (aka Tiki CMS/Groupware) 1.9.x …
2006-01-01
EPSS3.7%
pct 88
7.5
CVE-2007-5684DEB
Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attac…
2007-01-01
EPSS3.0%
pct 85
7.5
CVE-2006-6168DEB
tiki-register.php in TikiWiki before 1.9.7 allows remote attackers to trigger "notification-spa…
2006-01-01
EPSS2.7%
pct 83
7.5
CVE-2005-1925DEB
Multiple directory traversal vulnerabilities in Tikiwiki before 1.9.1 allow remote attackers to…
2005-01-01
EPSS2.6%
pct 83
7.5
CVE-2007-5682DEB
Incomplete blacklist vulnerability in tiki-graph_formula.php in TikiWiki before 1.9.8.2 allows …
2007-01-01
EPSS2.6%
pct 83
7.5
CVE-2005-0200DEB
TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp dire…
2005-01-01
EPSS2.4%
pct 82
4.3
CVE-2006-5703DEB
Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows rem…
2006-01-01
EPSS2.4%
pct 81
8.7
CVE-2025-34113ANC
An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 …
2025-01-01
EPSS2.1%
pct 79
7.5
CVE-2013-4715DEB
SQL injection vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LT…
2013-01-01
EPSS1.9%
pct 76
10.0
CVE-2007-6529DEB
Multiple unspecified vulnerabilities in TikiWiki before 1.9.9 have unknown impact and attack ve…
2007-01-01
EPSS1.9%
pct 76
4.3
CVE-2005-3283DEB
Cross-site scripting (XSS) vulnerability in TikiWiki before 1.9.1.1 allows remote attackers to …
2005-01-01
EPSS1.8%
pct 76
7.5
CVE-2016-10143DEB
A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on …
2016-01-01Pre-auth
EPSS1.8%
pct 76
7.5
CVE-2004-1386DEB
TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote atta…
2004-01-01
EPSS1.8%
pct 75
4.3
CVE-2006-3047DEB
Cross-site scripting (XSS) vulnerability in TikiWiki 1.9.3.2 and possibly earlier versions allo…
2006-01-01
EPSS1.8%
pct 75
4.3
CVE-2007-4554DEB
Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/…
2007-01-01
EPSS1.7%
pct 74
7.5
CVE-2010-1136DEB
The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers t…
2010-01-01
EPSS1.7%
pct 73
10.0
CVE-2008-3653DEB
Multiple unspecified vulnerabilities in TikiWiki CMS/Groupware before 2.0 have unknown impact a…
2008-01-01
EPSS1.6%
pct 73
4.3
CVE-2011-4551DEB
Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware befor…
2011-01-01
EPSS1.6%
pct 73
4.3
CVE-2007-6526DEB
Cross-site scripting (XSS) vulnerability in tiki-special_chars.php in TikiWiki before 1.9.9 all…
2007-01-01
EPSS1.6%
pct 71
7.5
CVE-2003-1574DEB
TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username wi…
2003-01-01
EPSS1.5%
pct 71
7.5
CVE-2010-1135DEB
The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user…
2010-01-01
EPSS1.5%
pct 71
9.3
CVE-2025-34111DEB
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware versio…
2025-01-01Pre-auth
EPSS1.5%
pct 71
9.8
CVE-2024-47919DEB
Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS …
2024-01-01Pre-auth
EPSS1.5%
pct 71
8.8
CVE-2020-29254DEB
TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauth…
2020-01-01Pre-auth
EPSS1.5%
pct 70
5.0
CVE-2005-3529DEB
tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain th…
2005-01-01
EPSS1.4%
pct 69
7.5
CVE-2006-4734DEB
Multiple SQL injection vulnerabilities in tiki-g-admin_processes.php in Tikiwiki 1.9.4 allow re…
2006-01-01
EPSS1.4%
pct 69
7.5
CVE-2006-3048DEB
SQL injection vulnerability in TikiWiki 1.9.3.2 and possibly earlier versions allows remote att…
2006-01-01
EPSS1.4%
pct 69
7.5
CVE-2010-1133DEB
Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote at…
2010-01-01
EPSS1.4%
pct 69
Select a vulnerability on the left to open the preview.