CVE-2018-14849: Tiki Tikiwiki Cms/groupware

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.

Affected products

  • Tiki Tikiwiki Cms/groupware: from 12.0, before 12.14 (fixed in 12.14); from 15.0, before 15.7 (fixed in 15.7); from 18.0, before 18.2 (fixed in 18.2)

Published 2018-08-13. Last modified 2026-06-17.