CVE-2025-32461

CRITICAL

Tiki <28.3 - Code Injection

Title source: llm
STIX 2.1

Description

wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.

Scores

CVSS v3 9.9
EPSS 0.0058
EPSS Percentile 69.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1336
Status published
Products (4)
Tiki/Tiki < 21.12
Tiki/Tiki 22 - 24.8
Tiki/Tiki 25 - 27.2
Tiki/Tiki 28 - 28.3
Published Apr 09, 2025
Tracked Since Feb 18, 2026