CVE-2025-32461: Critical severity tiki wiki cms groupware vulnerability
Published Apr 9, 2025
·Updated
wikipluginincludetpl in lib/wiki-plugins/wikipluginincludetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.
Affected Software
1 affected component
Tiki tiki<28.3
Event History
Apr 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
May 5, 57258
Event
via FIRST·06:24 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-32461?
CVE-2025-32461 is categorized as a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-32461?
To fix CVE-2025-32461, upgrade to Tiki versions 21.12, 24.8, 27.2, or 28.3.
3
What software versions are affected by CVE-2025-32461?
CVE-2025-32461 affects Tiki versions prior to 28.3.
4
What type of vulnerability is CVE-2025-32461?
CVE-2025-32461 is an input validation vulnerability related to improper handling of user input in an eval function.
5
Who is impacted by CVE-2025-32461?
Users and administrators of Tiki versions before 28.3 are impacted by CVE-2025-32461.