EIP-2026-112681

PRE-CVE

Tiki Wiki CMS Groupware 5.2 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112681. PoCs published by John Leitch.

AI-analyzed exploit summary The document describes a local file inclusion (LFI) and cross-site scripting (XSS) vulnerability in Tiki Wiki CMS Groupware. It provides example URIs demonstrating how an attacker can exploit these vulnerabilities to read local files or execute arbitrary script code in a user's browser.

Description

Tiki Wiki CMS Groupware 5.2 - Multiple Vulnerabilities

Exploits (1)

exploitdb WRITEUP VERIFIED
by John Leitch · textwebappsphp
https://www.exploit-db.com/exploits/15174

The document describes a local file inclusion (LFI) and cross-site scripting (XSS) vulnerability in Tiki Wiki CMS Groupware. It provides example URIs demonstrating how an attacker can exploit these vulnerabilities to read local files or execute arbitrary script code in a user's browser.

Classification
Writeup 90%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Tiki Wiki CMS Groupware 5.2 and prior to 3.8
No auth needed
Prerequisites: Access to the target application · Ability to craft malicious URIs
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026