← Vulnerability feed

Vulnerability record · CVE-2011-4558 · published 27 January 2020

CVE-2011-4558: Tiki injection vulnerability

Tiki · Tiki

Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.

7.2 CVSS 3.1 High EPSS 4.3% · top 9.3% CWE-74 · Injection
7.2CVSS 3.1 base score, v2 6.0
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-4558 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-15906Tiki improper restriction of authentication attempts vulnerabilitytiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.EPSS 27%8.8CVE-2023-22850Tiki deserialization of untrusted data vulnerabilityTiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.EPSS 1.2%8.8CVE-2023-22853Tiki code injection vulnerabilityTiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.EPSS 0.94%8.8CVE-2018-7304Tiki csv injection vulnerabilityTiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the vi…EPSS 1.2%7.2CVE-2023-22851Tiki unrestricted file upload vulnerabilityTiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.EPSS 1.0%6.5CVE-2023-22852Tiki cross-site request forgery vulnerabilityTiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.EPSS 0.32%6.1CVE-2020-16131Tiki cross-site scripting vulnerabilityTiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.EPSS 0.69%6.1CVE-2011-4455Tiki cross-site scripting vulnerabilityMultiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info…EPSS 0.95%

Source: NIST National Vulnerability Database (record CVE-2011-4558), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.