Find real vulnerabilities before they ship
Vulnerability Database › packagist › CVE-2018-7302
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
Base Score