VYPR
Unrated severityNVD Advisory· Published Feb 25, 2026· Updated Mar 5, 2026

SPIP jeux < 4.1.1 Reflected XSS via index Parameters

CVE-2026-27746

Description

The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_propre pipeline. The plugin incorporates untrusted request parameters into HTML output without proper output encoding, allowing attackers to inject arbitrary script content into pages that render a jeux block. When a victim is induced to visit a crafted URL, the injected content is reflected into the response and executed in the victim's browser context.

Affected products

2
  • Spip/Spipllm-fuzzy
    Range: <4.1.1
  • SPIP/jeuxv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.