CVE-2025-32461
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/04/2025
Last modified:
15/04/2026
Description
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.
Impact
Base Score 3.x
9.90
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://gitlab.com/tikiwiki/tiki/-/commit/406bea4f6c379a23903ecfd55e538d90fd669ab0
- https://gitlab.com/tikiwiki/tiki/-/commit/801ed912390c2aa6caf12b7b953e200f5d4bc0b1
- https://gitlab.com/tikiwiki/tiki/-/commit/9ffb4ab21bd86837370666ecd6afd868f3d7877a
- https://gitlab.com/tikiwiki/tiki/-/commit/be8dc1aa220fbceb07a7a5dc36416243afccd358
- https://gitlab.com/tikiwiki/tiki/-/commit/f3f36c1ac702479209acfcaec5789d2fd1f996bc
- https://tiki.org/article517
- https://tiki.org/article518
- http://seclists.org/fulldisclosure/2025/Jul/11



