Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tiki

First CVE: Apr 11, 2004Active for: 22 yearsTotal CVEs: 92
49.2
VTI Score
High

Tiki maintains a narrowly focused content-management and collaboration platform, TikiWiki CMS/Groupware, that despite its single-product portfolio has achieved a prominent position in the vulnerability landscape and remains embedded in a wide range of organizational wikis and collaborative deployments. The vulnerability footprint is characterized by a recurring pattern of web-application input-handling flaws—cross-site scripting, SQL injection, improper input validation, and cross-site request forgery—alongside information-disclosure weaknesses that reflect the platform's role as a user-facing, data-aggregating system. Public exploit code availability is an elevated tendency for this vendor's disclosures, making proof-of-concept tooling readily accessible for disclosed flaws. Defenders maintaining TikiWiki instances should prioritize vendor updates and treat this platform as a meaningful attack surface within organizational intranets; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
92
Total CVEs
More Total CVEs than 99% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tiki over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2004
22 years ago
Most Recent CVE
Mar 23, 2026
123 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (92 CVEs).

92 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-0911CRITICAL
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bann
Jul 12, 20129.883NOYES
CVE-2005-1921HIGH
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such a
Jul 5, 20057.578NOYES
CVE-2007-5423HIGH
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function.
Oct 12, 20077.577NOYES
CVE-2006-4602HIGH
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains
Sep 7, 20067.560NOYES
CVE-2006-5702MEDIUM
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchange
Nov 4, 20065.059NOYES
CVE-2020-15906CRITICAL
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
Oct 22, 20209.857NOYES
CVE-2010-4239CRITICAL
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
Oct 28, 20199.849NOYES
CVE-2011-4336MEDIUM
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
Jan 15, 20206.143NOYES
CVE-2012-5321MEDIUM
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "f
Oct 8, 20125.842NOYES
CVE-2025-34111CRITICAL
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.
Jul 15, 20259.838NOYES
View all 92 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products92 CVEs
59%
36%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network43 (46.7%)
Unknown49 (53.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (46.7%)
High0 (0.0%)
Unknown49 (53.3%)
User Interaction
None12 (13.0%)
Unknown49 (53.3%)
Required31 (33.7%)
Privileges Required
Low18 (19.6%)
High6 (6.5%)
None19 (20.7%)
Unknown49 (53.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (92 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
6.5% of CVEs· 98th percentile
Nuclei
4 CVEs
4.3% of CVEs· 95th percentile
ExploitDB
21 CVEs
22.8% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tiki.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tiki — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tiki's Products

View all 6 CNAs →

Top CWEs