← Vulnerability feed

Vulnerability record · CVE-2023-22853 · published 14 January 2023

CVE-2023-22853: Tiki code injection vulnerability

Tiki · Tiki

Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.

8.8 CVSS 3.1 High EPSS 0.94% · top 40.7% CWE-94 · Code injection
8.8CVSS 3.1 base score
0.94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://karmainsecurity.com/KIS-2023-02 Third Party Advisory
https://tiki.org/articles Vendor Advisory
https://karmainsecurity.com/KIS-2023-02 Third Party Advisory
https://tiki.org/articles Vendor Advisory

Track CVE-2023-22853 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-15906Tiki improper restriction of authentication attempts vulnerabilitytiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.EPSS 27%8.8CVE-2023-22850Tiki deserialization of untrusted data vulnerabilityTiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.EPSS 1.2%8.8CVE-2018-7304Tiki csv injection vulnerabilityTiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the vi…EPSS 1.2%7.2CVE-2023-22851Tiki unrestricted file upload vulnerabilityTiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.EPSS 1.0%7.2CVE-2011-4558Tiki injection vulnerabilityTiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.EPSS 4.3%6.5CVE-2023-22852Tiki cross-site request forgery vulnerabilityTiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.EPSS 0.32%6.1CVE-2020-16131Tiki cross-site scripting vulnerabilityTiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.EPSS 0.69%6.1CVE-2011-4455Tiki cross-site scripting vulnerabilityMultiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info…EPSS 0.95%

Source: NIST National Vulnerability Database (record CVE-2023-22853), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.