CVE-2020-15906: Tiki
Critical severity, CVSS 9.8. EPSS: 27.2% chance of exploitation in the next 30 days.
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
Affected products
- Tiki Tiki: from 16.3, before 21.2 (fixed in 21.2)
Published 2020-10-22. Last modified 2026-06-17.