CVE-2018-14850: Tiki Tikiwiki Cms/groupware

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.

Affected products

  • Tiki Tikiwiki Cms/groupware: from 12.0, before 12.14 (fixed in 12.14); from 15.0, before 15.7 (fixed in 15.7); from 18.0, before 18.2 (fixed in 18.2)

Published 2018-08-13. Last modified 2026-06-17.