CVE-2018-7302: Tiki
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
Affected products
- Tiki Tiki: version 17.1 only
Published 2018-02-21. Last modified 2026-06-17.