PT-2026-20844 · Spip · Spip

Arthur Deloffre

+2

·

Publicado

2026-02-19

·

Atualizado

2026-02-19

·

CVE-2025-71246

CVSS v3.1

4.7

Média

VetorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SPIP versions prior to 4.4.8
Description SPIP before version 4.4.8 contains a Cross-Site Scripting (XSS) issue in the public area due to inadequate detection of malicious content by the echapper html suspect() function. This allows an attacker to inject scripts that execute in a visitor’s browser. The SPIP security screen does not mitigate this issue.
Recommendations Update to SPIP version 4.4.8 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-71246

Produtos afetados

Spip