Tiki maintains a narrowly focused content-management and collaboration platform, TikiWiki CMS/Groupware, that despite its single-product portfolio has achieved a prominent position in the vulnerability landscape and remains embedded in a wide range of organizational wikis and collaborative deployments. The vulnerability footprint is characterized by a recurring pattern of web-application input-handling flaws—cross-site scripting, SQL injection, improper input validation, and cross-site request forgery—alongside information-disclosure weaknesses that reflect the platform's role as a user-facing, data-aggregating system. Public exploit code availability is an elevated tendency for this vendor's disclosures, making proof-of-concept tooling readily accessible for disclosed flaws. Defenders maintaining TikiWiki instances should prioritize vendor updates and treat this platform as a meaningful attack surface within organizational intranets; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tiki over time
Signals from CVEs in this vendor scope (92 CVEs).
92 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0911CRITICAL TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bann | Jul 12, 2012 | 9.8 | 83 | NO | YES |
CVE-2005-1921HIGH Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such a | Jul 5, 2005 | 7.5 | 78 | NO | YES |
CVE-2007-5423HIGH tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function. | Oct 12, 2007 | 7.5 | 77 | NO | YES |
CVE-2006-4602HIGH Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains | Sep 7, 2006 | 7.5 | 60 | NO | YES |
CVE-2006-5702MEDIUM Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchange | Nov 4, 2006 | 5.0 | 59 | NO | YES |
CVE-2020-15906CRITICAL tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts. | Oct 22, 2020 | 9.8 | 57 | NO | YES |
CVE-2010-4239CRITICAL Tiki Wiki CMS Groupware 5.2 has Local File Inclusion | Oct 28, 2019 | 9.8 | 49 | NO | YES |
CVE-2011-4336MEDIUM Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php. | Jan 15, 2020 | 6.1 | 43 | NO | YES |
CVE-2012-5321MEDIUM tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "f | Oct 8, 2012 | 5.8 | 42 | NO | YES |
CVE-2025-34111CRITICAL An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal. | Jul 15, 2025 | 9.8 | 38 | NO | YES |
Signals from CVEs in this vendor scope (92 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tiki.
Media articles that mention a CVE ID that affects a product developed by Tiki — matched by CVE ID, not by vendor name.