TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-printmultipages.php or (b) tiki-printpages.php; or (4) sendpages, (5) sendstructures, or (6) sendarticles parameter to tiki-sendobjects.php, which is not properly handled when processed by the unserialize function.
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
Tiki Wiki CMS Groupware 5.2 has CSRF
Tiki Wiki CMS Groupware 5.2 has XSS
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/includecalendar.php, (2) tiki-rsserror.php, or (3) tiki-watershedservice.php.
Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.