PT-2026-27195 · Tiki · Tiki

CVE-2024-46878

·

Published

2026-03-23

·

Updated

2026-03-23

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tiki versions prior to 26.4
Description A Cross-Site Scripting (XSS) issue exists in the page parameter of the tiki-editpage.php file. This allows attackers to execute arbitrary JavaScript code through a crafted payload, potentially leading to access of sensitive information or unauthorized actions.
Recommendations Update to version 26.4 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-46878

Affected Products

Tiki