CVE-2025-32461: Tiki

Critical severity, CVSS 9.9. EPSS: 0.9% chance of exploitation in the next 30 days.

wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.

Affected products

  • Tiki Tiki: before 21.12 (fixed in 21.12); from 22, before 24.8 (fixed in 24.8); from 25, before 27.2 (fixed in 27.2); from 28, before 28.3 (fixed in 28.3)

Published 2025-04-09. Last modified 2026-06-17.