CVE-2024-46878

A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tiki:tiki:*:*:*:*:*:*:*:*

History

02 Apr 2026, 20:11

Type Values Removed Values Added
CPE cpe:2.3:a:tiki:tiki:*:*:*:*:*:*:*:*
First Time Tiki tiki
Tiki
References () https://github.com/ColdFusionX/CVE-2024-46878-TikiCMS-XSS - () https://github.com/ColdFusionX/CVE-2024-46878-TikiCMS-XSS - Exploit, Third Party Advisory
References () https://tiki.org/article514-New-Security-Updates-Released-for-Tiki-27-x-LTS-26-x-and-24-x-LTS-and-Upgrade-is-Strongly-Recommended - () https://tiki.org/article514-New-Security-Updates-Released-for-Tiki-27-x-LTS-26-x-and-24-x-LTS-and-Upgrade-is-Strongly-Recommended - Release Notes
References () https://tiki.org/tiki-newsletters.php?nlId=8&info=1 - () https://tiki.org/tiki-newsletters.php?nlId=8&info=1 - Product

24 Mar 2026, 16:16

Type Values Removed Values Added
References () https://github.com/ColdFusionX/CVE-2024-46878-TikiCMS-XSS - () https://github.com/ColdFusionX/CVE-2024-46878-TikiCMS-XSS -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
Summary
  • (es) Una vulnerabilidad de cross-site scripting (XSS) existe en el parámetro 'page' de tiki-editpage.PHP en Tiki versión 26.3 y anteriores. Esta vulnerabilidad permite a los atacantes ejecutar código JavaScript arbitrario mediante una carga útil manipulada, lo que puede llevar a un acceso potencial a información sensible o acciones no autorizadas.
CWE CWE-79

23 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 20:16

Updated : 2026-04-02 20:11


NVD link : CVE-2024-46878

Mitre link : CVE-2024-46878

CVE.ORG link : CVE-2024-46878


JSON object : View

Products Affected

tiki

  • tiki
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')