VYPR

Spip

by Spip

Source repositories

CVEs (84)

  • CVE-2024-53619MedNov 26, 2024
    risk 0.41cvss 6.3epss 0.01

    An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

  • CVE-2026-27746MedFeb 25, 2026
    risk 0.40cvss 6.1epss 0.00

    The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_propre pipeline. The plugin incorporates untrusted request parameters into HTML output without proper output encoding, allowing attackers to inject arbitrary…

  • CVE-2026-27474MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML tags, allowing an attacker to inject malicious…

  • CVE-2026-26223MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute malicious scripts. The fix adds a sandbox…

  • CVE-2025-71244MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login…

  • CVE-2025-71241MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious scripts. This vulnerability is mitigated by the…

  • CVE-2024-23659MedJan 19, 2024
    risk 0.40cvss 6.1epss 0.00

    SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.

  • CVE-2023-52322MedJan 4, 2024
    risk 0.40cvss 6.1epss 0.00

    ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.

  • CVE-2022-28959MedMay 19, 2022
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.

  • CVE-2019-16393MedSep 17, 2019
    risk 0.40cvss 6.1epss 0.01

    SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.

  • CVE-2019-16392MedSep 17, 2019
    risk 0.40cvss 6.1epss 0.01

    SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.

  • CVE-2017-15736MedOct 22, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web script or HTML via a crafted string, as demonstrated by a PGP field, related to prive/objets/contenu/auteur.html and ecrire/inc/texte_mini.php.

  • CVE-2016-7981MedJan 18, 2017
    risk 0.40cvss 6.1epss 0.09

    Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.

  • CVE-2016-9998MedDec 17, 2016
    risk 0.40cvss 6.1epss 0.01

    SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/info_plugin.php involving the `$plugin` parameter, as demonstrated by a /ecrire/?exec=info_plugin URL.

  • CVE-2016-9997MedDec 17, 2016
    risk 0.40cvss 6.1epss 0.01

    SPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/puce_statut.php involving the `$id` parameter, as demonstrated by a /ecrire/?exec=puce_statut URL.

  • CVE-2016-9152MedDec 5, 2016
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in ecrire/exec/plonger.php in SPIP 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the rac parameter.

  • CVE-2026-26345MedFeb 19, 2026
    risk 0.35cvss 5.4epss 0.00

    SPIP before 4.4.8 contains a stored cross-site scripting (XSS) vulnerability in the public area triggered in certain edge-case usage patterns. The echapper_html_suspect() function does not adequately sanitize user-controlled content, allowing authenticated users with…

  • CVE-2025-71240MedFeb 19, 2026
    risk 0.35cvss 5.4epss 0.00

    SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a victim's browser.

  • CVE-2022-26847MedMar 10, 2022
    risk 0.35cvss 5.3epss 0.01

    SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.

  • CVE-2021-44120MedJan 26, 2022
    risk 0.35cvss 5.4epss 0.01

    SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes…