CVE-2020-15906: Tiki

Critical severity, CVSS 9.8. EPSS: 27.2% chance of exploitation in the next 30 days.

tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

Affected products

  • Tiki Tiki: from 16.3, before 21.2 (fixed in 21.2)

Published 2020-10-22. Last modified 2026-06-17.