CVE-2018-7188: Tiki Tikiwiki Cms/groupware
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.
Affected products
- Tiki Tikiwiki Cms/groupware: before 18 (fixed in 18)
Published 2018-02-16. Last modified 2026-06-17.