| | Rating | Summary | Priority | Data type | Version | Feature | Created |
 | 1 | User Information Page shows non-public wiki page titles | 7 | Bug (error message, broken, etc) | 2.x 3.x | Permission Security Wiki (history, page rename, etc) | 2008-07 |
 | 6 | RSS Calendar Security problem - anonymous users allowed access to secured calendar via RSS link | 7 | | | Calendar Category Group RSS Security | 2007-10 |
 | - | No spam protection for shoutbox users | 7 | Bug : Usability (trouble to accomplish task) | 1.9.x | Security Shoutbox | 2008-06 |
 | 1 | Need stronger CapCha | 7 | Feature request | 2.x | Security | 2008-06 |
 | - | Warning: is_dir(): Stat failed for ./img/wiki_up/tiki1/... intiki-admin_security.php?check_files | 6 | Bug : Usability (trouble to accomplish task) | 2.x | All / Undefined Security | 2006-09 |
 | - | Banning users ( tiki-admin_banning.php ) doesn't work for me at doc.tw.o | 6 | Bug : Usability (trouble to accomplish task) | 1.9.x | Security User Administration (Registration, Login & Banning) | 2007-06 |
 | 6 | Wiki cache & plugins: WYSIWYCA problem when admin visits the page (and creates the cache) | 6 | Bug (error message, broken, etc) | 3.x | Article Cache Security Trackers Wiki (history, page rename, etc) Wiki Plugin (extends basic syntax) | 2007-08 |
 | 4 | Registration Page does not display and password suggestion does not consider security settings. | 6 | Bug : Usability (trouble to accomplish task) Feature request | 1.9.x | Security User Administration (Registration, Login & Banning) | 2008-01 |
 | 1 | Image attachements are not saved unique | 5 | Bug (error message, broken, etc) Bug : Usability (trouble to accomplish task) | 1.8.x 1.9.x | Security Wiki (history, page rename, etc) | 2006-04 |
 | - | Security bug which bypasses directory site validation. | 5 | Bug (error message, broken, etc) | 1.9.x | Directory (of hyperlinks) Security | 2006-07 |
 | 2 | binddb and bindpw not used when binding to LDAP | 5 | Bug (error message, broken, etc) Patch | 1.9.x | External Authentication (LDAP, AD, PAM, CAS, etc) Security User Administration (Registration, Login & Banning) | 2007-10 |
 | 2 | Secdb for all files (not just php) | 5 | Feature request | 1.9.x 2.x | Administration Installer (profiles, upgrades and server-related issues) Security | 2007-11 |
 | - | Automatic SVN commit of secdb and syncdb | 5 | Community projects | 2.x | Installer (profiles, upgrades and server-related issues) Security | 2008-04 |
 | 2 | mail-in provides no security | 4 | Bug (error message, broken, etc) | 1.9.x | Article Mail-in Security Wiki (history, page rename, etc) | 2006-05 |
 | 4 | Better protection against accidental site breakage with improper use of code in modules + template | 4 | Bug (error message, broken, etc) Bug : Usability (trouble to accomplish task) Feature request | 1.9.x | Administration Installer (profiles, upgrades and server-related issues) Modules Security Site Identity Templates (Smarty) | 2007-04 |
 | - | Trackback pings should not use fopen to open urls. | 3 | Bug (error message, broken, etc) | 1.9.x 2.x | Blog Security XML RPC | 2005-05 |
 | - | wiki-edit: footnotes allows html | 3 | Bug (error message, broken, etc) | 1.9.x | Security Wiki (history, page rename, etc) | 2006-08 |
 | - | dynamic contents in userdefined modules crashes tiki | 3 | | 1.9.x | Dynamic Content Modules Security Wiki Syntax (text area, parser, external wiki, etc) | 2006-08 |
 | 0 | Built it TPL editor removes Javascript from the Templates | 3 | Bug : Usability (trouble to accomplish task) Feature request | 2.x | Security Theme: Look & feel, Styles, CSS, Theme Control Center | 2005-04 |
 | - | My site totally dead: Warning: ini_set() has been disabled for security reasons | 3 | | 1.9.x | Security | 2007-06 |
 | 7 | Restrict possible characters in usernames | 3 | Bug (error message, broken, etc) Bug : Usability (trouble to accomplish task) Feature request | 2.x | Security User Administration (Registration, Login & Banning) | 2007-07 |
 | 1 | Trackers: ratings fake vote by URL | 3 | Bug (error message, broken, etc) | 1.9.x A *.tikiwiki.org site | Rating Security Trackers | 2007-12 |
 | 1 | Category plugin lists objects even without perms | 3 | | 1.9.x 2.x | Category Security Wiki Plugin (extends basic syntax) | 2008-01 |
 | - | Instantaneous visual feedback of password strength | 3 | Feature request | 2.x | Security User Administration (Registration, Login & Banning) | 2008-06 |
 | 2 | Path disclosure bug in trackers | 2 | Bug (error message, broken, etc) | 1.9.x | Security Trackers | 2007-06 |
 | 1 | Easy way to deal with SSL when using external images or scripts | 1 low | Feature request | 2.x | Security Stats | 2008-02 |
 | - | Security DB and mods don't work together | 1 low | Bug : Usability (trouble to accomplish task) Feature request | 2.x | Mods Security | 2008-02 |
 | 2 | File gallery: Virus checker | | Feature request | 2.x | File Gallery Security | 2008-04 |
| | Rating | Summary | Priority | Data type | Version | Feature | Created |
 | - | tikiwiki version 1.9.5 (CVS) -Sirius- mysql password disclosure & xss | 9 high | Bug (error message, broken, etc) | 1.9.x 2.x | Security | 2006-11 |
 | - | Vulnerability in registrating | 9 high | | 1.9.x | Security User Administration (Registration, Login & Banning) | 2007-01 |
 | 2 | XSS vulnerability issue B96 | 9 high | Bug (error message, broken, etc) | 1.9.x | Security | 2008-01 |
 | - | tiki_p_search makes users "admin" | 8 | Bug (error message, broken, etc) Bug : Consistency | 2.x | Administration Search Security User Administration (Registration, Login & Banning) | 2008-03 |
 | 3 | Forum security issue: Ref: H56 | 7 | Bug (error message, broken, etc) | 1.9.x | Forum Security | 2007-07 |
 | 2 | Wiki cache & plugins: WYSIWYCA problem when admin visits the page (and creates the cache) | 6 | Bug (error message, broken, etc) | 1.9.x | Cache Database MySQL Security Wiki (history, page rename, etc) Wiki Plugin (extends basic syntax) | 2007-06 |
 | - | image gallery: sort_mode=filesize causes mysql error and path disclosure | 5 | Bug (error message, broken, etc) | 1.9.x 2.x | Image Gallery Security | 2007-09 |
 | - | Change Crypt passwords method | 4 | Feature request | 2.x 3.x | Security User Administration (Registration, Login & Banning) | 2008-07 |
 | - | No access permission on articles----articles accessible by articleID for any group | | Feature request | 1.9.x | Article Security | 2007-01 |
 | - | CVE-2006-6457 tikiwiki vulnerable | | Bug (error message, broken, etc) Support request | 1.9.x | All / Undefined Security | 2007-01 |
 | - | TikiWiki 2.0: Odd Tags get Inserted into HTML Code | | Bug (error message, broken, etc) Bug : Consistency Bug : Usability (trouble to accomplish task) | 2.x | Security Wiki Syntax (text area, parser, external wiki, etc) | 2008-08 |
Last Modified Comments