Search CVE reports


Toggle filters

1 – 10 of 60 results


CVE-2026-27475

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-27474

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-27473

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-27472

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is a valid remote URL, allowing...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-26345

Medium priority
Needs evaluation

SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the public area for certain edge-case usage patterns. The echapper_html_suspect() function does not adequately detect all forms of malicious content, permitting an attacker to...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-26223

Medium priority
Needs evaluation

SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-71244

Medium priority
Needs evaluation

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login....

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-71242

Medium priority
Needs evaluation

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-71241

Medium priority
Needs evaluation

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-71240

Medium priority
Needs evaluation

SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages