First published: Wed Apr 09 2025(Updated: )
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tiki Wiki CMS Groupware | <28.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32461 is categorized as a high-severity vulnerability due to its potential for remote code execution.
To fix CVE-2025-32461, upgrade to Tiki versions 21.12, 24.8, 27.2, or 28.3.
CVE-2025-32461 affects Tiki versions prior to 28.3.
CVE-2025-32461 is an input validation vulnerability related to improper handling of user input in an eval function.
Users and administrators of Tiki versions before 28.3 are impacted by CVE-2025-32461.