CVE-2024-46878 - Vulnerability Analysis
N/aLast Updated: March 23, 2026
Tiki - Stored XSS
Published: March 23, 2026Updated: March 23, 2026PoC Available
Overview
Tiki <= 26.3 contains a stored XSS caused by improper sanitization of the "page" parameter in tiki-editpage.php, letting attackers execute arbitrary JavaScript code, exploit requires crafted payload.
Severity & Score
Severity: N/a
Impact
Attackers can execute arbitrary JavaScript, potentially stealing sensitive information or performing unauthorized actions.
Mitigation
Update to the latest version beyond 26.3.
References
Related Resources
Details
- CVE ID
- CVE-2024-46878
- Severity
- N/a
- Type
- stored_xss
- Status
- new
CVSS Metrics
N/A