Tiki Tiki Wiki CMS/Groupware 14.1

CPE Details

Tiki Tiki Wiki CMS/Groupware 14.1
14.1
2019-10-23
18h34 +00:00
2019-10-23
18h34 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:tiki:tikiwiki_cms\/groupware:14.1:*:*:*:*:*:*:*

Informations

Vendor

tiki

Product

tikiwiki_cms\/groupware

Version

14.1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2020-8966 2020-04-01 20h18 +00:00 There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a legitimate web page.
6.5
Moyen
CVE-2018-20719 2019-01-15 15h00 +00:00 In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.
8.8
Haute
CVE-2018-7188 2018-02-16 18h00 +00:00 An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.
5.4
Moyen
CVE-2016-7394 2018-02-06 15h00 +00:00 tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
6.1
Moyen
CVE-2017-9145 2017-06-26 11h00 +00:00 TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.
6.1
Moyen