CVE-2025-34111
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of the web server. The vulnerable component does not enforce file type validation, allowing attackers to craft a POST request to upload executable PHP payloads through the ELFinder interface exposed at /vendor_extra/elfinder/.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 2.18%
- CWE
- CWE-434, CWE-306, CWE-20
- Published
- 2025-07-15
- Last modified
- 2026-05-15
Affected products
- Tiki Software Community Association Wiki CMS Groupware
- Tiki Software Community Association Wiki CMS Groupware
Weakness type
Related vulnerabilities
- CVE-2026-54611 — InstantCMS has Remote Code Execution in package installer
- CVE-2026-86666 — aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload
- CVE-2026-50093 — A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173),...
- CVE-2026-86305 — light0011 cms Upload.class.php upload unrestricted upload
- CVE-2026-86272 — Beijing Meite Software Technology U+Smart Enjoyment WebSite UploadFormImg.ashx unrestricted upload
- CVE-2026-86239 — liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload
- CVE-2026-44402 — Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi
- CVE-2026-12483 — LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler