PT-2026-20843 · Spip · Spip
Arthur Deloffre
+2
·
Published
2026-02-19
·
Updated
2026-02-19
·
CVE-2025-71245
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SPIP versions prior to 4.4.8
Description
SPIP before version 4.4.8 contains a Cross-Site Scripting (XSS) issue in the private area due to improper handling of iframe tags. The application does not adequately sandbox or escape iframe content within the back-office, which allows an attacker to inject and execute malicious scripts. The vulnerability is not addressed by the SPIP security screen.
Recommendations
Update to SPIP version 4.4.8 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spip