VYPR

Spip

by Spip

Source repositories

CVEs (79)

  • CVE-2025-71241MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious scripts. This vulnerability is mitigated by the…

  • CVE-2024-23659MedJan 19, 2024
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.

  • CVE-2023-52322MedJan 4, 2024
    risk 0.40cvss 6.1epss 0.00

    ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.

  • CVE-2022-28959MedMay 19, 2022
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.

  • CVE-2019-16393MedSep 17, 2019
    risk 0.40cvss 6.1epss 0.01

    SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.

  • CVE-2019-16392MedSep 17, 2019
    risk 0.40cvss 6.1epss 0.01

    SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.

  • CVE-2017-15736MedOct 22, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web script or HTML via a crafted string, as demonstrated by a PGP field, related to prive/objets/contenu/auteur.html and ecrire/inc/texte_mini.php.

  • CVE-2016-7981MedJan 18, 2017
    risk 0.40cvss 6.1epss 0.08

    Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.

  • CVE-2016-9998MedDec 17, 2016
    risk 0.40cvss 6.1epss 0.01

    SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/info_plugin.php involving the `$plugin` parameter, as demonstrated by a /ecrire/?exec=info_plugin URL.

  • CVE-2016-9997MedDec 17, 2016
    risk 0.40cvss 6.1epss 0.01

    SPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/puce_statut.php involving the `$id` parameter, as demonstrated by a /ecrire/?exec=puce_statut URL.

  • CVE-2016-9152MedDec 5, 2016
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in ecrire/exec/plonger.php in SPIP 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the rac parameter.

  • CVE-2026-26345MedFeb 19, 2026
    risk 0.35cvss 5.4epss 0.00

    SPIP before 4.4.8 contains a stored cross-site scripting (XSS) vulnerability in the public area triggered in certain edge-case usage patterns. The echapper_html_suspect() function does not adequately sanitize user-controlled content, allowing authenticated users with…

  • CVE-2025-71240MedFeb 19, 2026
    risk 0.35cvss 5.4epss 0.00

    SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a victim's browser.

  • CVE-2022-26847MedMar 10, 2022
    risk 0.35cvss 5.3epss 0.01

    SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.

  • CVE-2021-44120MedJan 26, 2022
    risk 0.35cvss 5.4epss 0.01

    SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes…

  • CVE-2021-44118MedJan 26, 2022
    risk 0.35cvss 5.4epss 0.01

    SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by…

  • CVE-2019-16394MedSep 17, 2019
    risk 0.35cvss 5.3epss 0.08

    SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.

  • CVE-2024-53620MedNov 26, 2024
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.

  • CVE-2026-27472MedFeb 19, 2026
    risk 0.28cvss 4.3epss 0.00

    SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is a valid remote URL, allowing an authenticated attacker to make the server issue…

  • CVE-2026-48832LowMay 24, 2026
    risk 0.23cvss 3.5epss 0.00

    action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.