CVE-2018-7290: Tiki Tikiwiki Cms/groupware

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.

Affected products

  • Tiki Tikiwiki Cms/groupware: from 12.0, before 12.13 (fixed in 12.13); from 15.0, before 15.6 (fixed in 15.6); from 17.0, before 17.2 (fixed in 17.2); version 18.0 only

Published 2018-03-09. Last modified 2026-06-17.