PT-2026-27195 · Tiki · Tiki
Published
2026-03-23
·
Updated
2026-03-23
·
CVE-2024-46878
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tiki versions prior to 26.4
Description
A Cross-Site Scripting (XSS) issue exists in the
page parameter of the tiki-editpage.php file. This allows attackers to execute arbitrary JavaScript code through a crafted payload, potentially leading to access of sensitive information or unauthorized actions.Recommendations
Update to version 26.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tiki