CVE-2018-7302: Tiki

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.

Affected products

  • Tiki Tiki: version 17.1 only

Published 2018-02-21. Last modified 2026-06-17.