CVE-2025-34111CRITICAL 9.8EPSS p71.3%

CVE-2025-34111CVE-2025-34111

Description

An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of the web server. The vulnerable component does not enforce file type validation, allowing attackers to craft a POST request to upload executable PHP payloads through the ELFinder interface exposed at /vendor_extra/elfinder/.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.52% probability of exploitation · percentile 71.3% · 2026-06-18T12:00:27Z
Published2025-07-15
Last modified2025-10-03

Underlying weaknesses· 3

CWE-20CWE-306CWE-434

References

  1. https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/tikiwiki_upload_exec.rb
  2. https://tiki.org/article434-Security-update-Tiki-15-2-Tiki-14-4-and-Tiki-12-9-released
  3. https://www.exploit-db.com/exploits/40091
  4. https://www.vulncheck.com/advisories/tiki-wiki-el-finder-unauthenticated-file-upload-rce

3

TypeTargetConfidenceTier
WeaknessImproper Input Validationcwe-200%live
WeaknessMissing Authentication for Critical Functioncwe-3060%live
WeaknessUnrestricted Upload of File with Dangerous Typecwe-4340%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-32461
CVE
CVE-2025-11456
CVE
CVE-2025-46001
CVE
CVE-2025-11170
CVE
CVE-2025-67164
CVE
CVE-2025-29401
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.