Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
- https://websecnerd.blogspot.in/2018/01/tiki-wiki-cms-groupware-17.html
No PoCs found on GitHub currently.