CVE-2018-20719: Tiki Tikiwiki Cms/groupware

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.

Affected products

  • Tiki Tikiwiki Cms/groupware: before 17.2 (fixed in 17.2)

Published 2019-01-15. Last modified 2026-06-17.