CVE-2025-32461
CRITICALTiki < 21.12, 22-24.7, 25-27.1, 28-28.2 - Remote Code Execution via wikiplugin_includetpl Eval
Title source: llmDescription
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.
References (8)
Core 8
Core References
Various Sources
https://tiki.org/article517
Various Sources
https://tiki.org/article518
Mailing List
http://seclists.org/fulldisclosure/2025/Jul/11
Scores
CVSS v3
9.9
EPSS
0.0078
EPSS Percentile
50.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-1336
Status
published
Products (4)
Tiki/Tiki
< 21.12
Tiki/Tiki
22 - 24.8
Tiki/Tiki
25 - 27.2
Tiki/Tiki
28 - 28.3
Published
Apr 09, 2025
Tracked Since
Feb 18, 2026