← Vulnerability feed

Vulnerability record · CVE-2020-15906 · published 22 October 2020

CVE-2020-15906: Tiki improper restriction of authentication attempts vulnerability

Tiki · Tiki

tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

9.8 CVSS 3.1 Critical EPSS 27% · top 2.0% CWE-307 · Improper restriction of authentication attempts
9.8CVSS 3.1 base score, v2 7.5
27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-15906 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-22850Tiki deserialization of untrusted data vulnerabilityTiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.EPSS 1.2%8.8CVE-2023-22853Tiki code injection vulnerabilityTiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.EPSS 0.94%8.8CVE-2018-7304Tiki csv injection vulnerabilityTiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the vi…EPSS 1.2%7.2CVE-2023-22851Tiki unrestricted file upload vulnerabilityTiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.EPSS 1.0%7.2CVE-2011-4558Tiki injection vulnerabilityTiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.EPSS 4.3%6.5CVE-2023-22852Tiki cross-site request forgery vulnerabilityTiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.EPSS 0.32%6.1CVE-2020-16131Tiki cross-site scripting vulnerabilityTiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.EPSS 0.69%6.1CVE-2011-4455Tiki cross-site scripting vulnerabilityMultiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info…EPSS 0.95%

Source: NIST National Vulnerability Database (record CVE-2020-15906), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.