CVE-2024-46878: Tiki
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.
Affected products
- Tiki Tiki: before 27.1 (fixed in 27.1)
Published 2026-03-23. Last modified 2026-06-17.