Known Vulnerabilities for Tikiwiki Cms/groupware by Tiki
Listed below are 10 of the newest known vulnerabilities associated with "Tikiwiki Cms/groupware" by "Tiki".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-36551 json | TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This ... | 5.4 - MEDIUM | 2021-10-28 | 2021-11-02 |
| CVE-2021-36550 json | TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.p... | 5.4 - MEDIUM | 2021-10-28 | 2021-11-02 |
| CVE-2020-29254 json | TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to ... | 8.8 - HIGH | 2020-12-11 | 2020-12-14 |
| CVE-2020-8966 json | There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Ti... | 6.1 - MEDIUM | 2020-04-01 | 2020-04-03 |
| CVE-2019-15314 json | tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tik... | 5.4 - MEDIUM | 2019-08-22 | 2019-08-28 |
| CVE-2018-20719 json | In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parame... | 8.8 - HIGH | 2019-01-15 | 2019-01-18 |
| CVE-2018-14850 json | Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain admin... | 5.4 - MEDIUM | 2018-08-13 | 2018-10-10 |
| CVE-2018-14849 json | Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/pa... | 5.4 - MEDIUM | 2018-08-13 | 2018-10-10 |
| CVE-2018-7303 json | The Calendar component in Tiki 17.1 allows HTML injection. | 5.4 - MEDIUM | 2018-02-21 | 2018-03-13 |
| CVE-2018-7290 json | Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1. | 5.4 - MEDIUM | 2018-03-09 | 2018-03-27 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tiki | Tikiwiki Cms/groupware | 9.7 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 9.6 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 9.5 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 9.4 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 9.3 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 9.2 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 9.2 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 9.1 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 9.0 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 9.0 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 9.0 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 9.0 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 8.4 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 8.3 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 8.2 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 8.1 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 8.0 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 7.2 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 7.1 | |||
| Application | Tiki | Tikiwiki Cms/groupware | 7.0 |