VYPR
Medium severity6.1NVD Advisory· Published Feb 25, 2026· Updated Jun 17, 2026

CVE-2026-27746

CVE-2026-27746

Description

The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_propre pipeline. The plugin incorporates untrusted request parameters into HTML output without proper output encoding, allowing attackers to inject arbitrary script content into pages that render a jeux block. When a victim is induced to visit a crafted URL, the injected content is reflected into the response and executed in the victim's browser context.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:spip:jeux:*:*:*:*:*:*:*:*
    Range: <4.1.1
  • Spip/Spipllm-fuzzy
    Range: <4.1.1
  • SPIP/jeuxv5
    Range: 0

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.