Vulnerabilities > Tiki > Tikiwiki CMS Groupware > 8.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-04-01 | CVE-2020-8966 | Cross-site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. | 4.3 |
2020-02-12 | CVE-2013-6022 | Cross-site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code. | 4.3 |
2019-01-15 | CVE-2018-20719 | SQL Injection vulnerability in Tiki Tikiwiki Cms/Groupware In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter. | 6.5 |
2018-02-16 | CVE-2018-7188 | Cross-site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php. | 3.5 |
2018-02-06 | CVE-2016-7394 | Cross-site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie. | 4.3 |
2012-10-08 | CVE-2012-5321 | Improper Input Validation vulnerability in Tiki Tikiwiki Cms/Groupware 8.3 tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection." | 5.8 |