TikiWiki CMS/Groupware Security HeadQuarter
Disclose a vulnerability
To allow us time to patch the system, please report the vulnerability using the
bug tracking system (you need to log in) using the category "security" but
without detailing the vulnerability so it cannot be exploited AND please
contact the security squad with full details and we'll deal with your input.
For more information:
Full Disclosure Policy (RFPolicy) v2.0
To be notified of new releases
New releases are announced in many places, including Freshmeat.
- You need to create an account and login there
- Visit Tiki page
- Click "Subscribe"
Tips to enhance security
- Keep your TikiWiki up to date. This is often overlooked!
- Check your server configuration with a script like phpsecinfo
- Check your server & installation using: doc.tikiwiki.org/security+admin
- Have your server professionally installed and kept up to date (PHP, Apache, Linux, etc.)
- Use strong passwords and set a password policy
- Only activate the features you need. Each feature is a potential security vulnerability. If the feature is turned off, it can't be used (starting in 1.9.11)
- If you are using permissions to restrict certain parts of the site, apply the permissions on each item (ex.: wiki page, file gallery, etc) instead of permissions via categories because this has had issues in the past. It's a complex feature and it can easily be misconfigured.
- Setup and test a backup procedure
Coming soon
Work in ongoing for the
TikiWiki Remote Instance Manager. This will be very useful to manage large numbers of TikiWiki instances.
Click any graph to see details at Secunia.com
4.x
no vulnerability reported as of 2009-12-27
3.x
no vulnerability reported as of 2009-12-27
2.x
1.x