← Vulnerability feed

Vulnerability record · CVE-2023-22850 · published 14 January 2023

CVE-2023-22850: Tiki deserialization of untrusted data vulnerability

Tiki · Tiki

Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.

8.8 CVSS 3.1 High EPSS 1.2% · top 33.9% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://karmainsecurity.com/KIS-2023-03 ExploitThird Party Advisory
https://tiki.org/articles Vendor Advisory
https://karmainsecurity.com/KIS-2023-03 ExploitThird Party Advisory
https://tiki.org/articles Vendor Advisory

Track CVE-2023-22850 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-15906Tiki improper restriction of authentication attempts vulnerabilitytiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.EPSS 27%8.8CVE-2023-22853Tiki code injection vulnerabilityTiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.EPSS 0.94%8.8CVE-2018-7304Tiki csv injection vulnerabilityTiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the vi…EPSS 1.2%7.2CVE-2023-22851Tiki unrestricted file upload vulnerabilityTiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.EPSS 1.0%7.2CVE-2011-4558Tiki injection vulnerabilityTiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.EPSS 4.3%6.5CVE-2023-22852Tiki cross-site request forgery vulnerabilityTiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.EPSS 0.32%6.1CVE-2020-16131Tiki cross-site scripting vulnerabilityTiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.EPSS 0.69%6.1CVE-2011-4455Tiki cross-site scripting vulnerabilityMultiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info…EPSS 0.95%

Source: NIST National Vulnerability Database (record CVE-2023-22850), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.