TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200.
CVE-2004-1386
NONECVSS 0.0
0.0
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
- No confirmed exploitation signals yet
CISA-KEV: Not listedEPSS: 2%CVSS: —Exploit: NoneExposed: 0
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- —
- EG Score
- 0.0(none)
- EPSS
- 76.3%
- KEV
- Not listed
Published
December 31, 2004
Last Modified
June 16, 2026
References (14)
- cve@mitrehttp://securitytracker.com/id?1012700
- cve@mitrehttp://tikiwiki.org/tiki-read_article.php?articleId=97
- cve@mitrehttp://www.ciac.org/ciac/bulletins/p-084.shtml
- cve@mitrehttp://www.gentoo.org/security/en/glsa/glsa-200501-12.xml
- cve@mitrehttp://www.osvdb.org/12628
- cve@mitrehttp://www.securityfocus.com/bid/12110
- cve@mitrehttps://exchange.xforce.ibmcloud.com/vulnerabilities/18691
- af854a3a-2127-422b-91ae-364da2661108http://securitytracker.com/id?1012700
- af854a3a-2127-422b-91ae-364da2661108http://tikiwiki.org/tiki-read_article.php?articleId=97
- af854a3a-2127-422b-91ae-364da2661108http://www.ciac.org/ciac/bulletins/p-084.shtml
- af854a3a-2127-422b-91ae-364da2661108http://www.gentoo.org/security/en/glsa/glsa-200501-12.xml
- af854a3a-2127-422b-91ae-364da2661108http://www.osvdb.org/12628
- af854a3a-2127-422b-91ae-364da2661108http://www.securityfocus.com/bid/12110
- af854a3a-2127-422b-91ae-364da2661108https://exchange.xforce.ibmcloud.com/vulnerabilities/18691
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Frequently asked(4)
What is CVE-2004-1386?
CVE-2004-1386 is a none vulnerability published on December 31, 2004. TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200.
When was CVE-2004-1386 disclosed?
CVE-2004-1386 was first published in the National Vulnerability Database on December 31, 2004, with the most recent update on June 16, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2004-1386 actively exploited?
CVE-2004-1386 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 76.3% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
How do I remediate CVE-2004-1386?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2004-1386, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2004-1386
Is Your Infrastructure Affected by CVE-2004-1386?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.