PT-2026-20854 · Spip · Spip

Arthur Deloffre

+2

·

Published

2026-01-01

·

Updated

2026-02-23

·

CVE-2026-26345

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SPIP versions prior to 4.4.8
Description SPIP before version 4.4.8 contains a Cross-Site Scripting (XSS) issue in the public area due to insufficient detection of malicious content by the echapper html suspect() function. This allows an attacker to inject scripts that can execute in a visitor’s browser. The SPIP security screen does not mitigate this issue.
Recommendations Update SPIP to version 4.4.8 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-26345

Affected Products

Spip