CVE-2018-7303: Tiki Tikiwiki Cms/groupware

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

The Calendar component in Tiki 17.1 allows HTML injection.

Affected products

  • Tiki Tikiwiki Cms/groupware: version 17.1 only

Published 2018-02-21. Last modified 2026-06-17.