Version Enumeration via Last-Modified Header
When a target does not disclose its software version directly, cache metadata can provide a useful clue. Static files are often served with a Last-Modified response header that reveals when the file was deployed.
Last-Modified
Modern web servers commonly cache JavaScript, CSS, and image files. The Last-Modified header tells clients when the origin believes a resource was last changed. See MDN’s Last-Modified header reference.
Look for a static file belonging to the software under investigation and inspect its Last-Modified response header.
Example: Tiki Wiki CMS
I tried to find the Tiki Wiki version through generator metadata, source comments, a ?v parameter, and other techniques without success. Then I noticed that the target returned an unusually old Last-Modified value:

Using Google’s after:YYYY-MM-DD search operator, I searched specifically for vulnerabilities and exploits published after that deployment date:

The target turned out to be vulnerable to the matching exploit. Alternatively, Google’s custom date-range tool can help identify release notes and estimate a software version compatible with the Last-Modified date:

Happy hacking ;)