PT-2026-20914 · Spip · Spip

Dorian Piette

·

Published

2026-01-01

·

Updated

2026-02-23

·

CVE-2026-27473

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SPIP versions prior to 4.4.9
Description SPIP versions prior to 4.4.9 contain a Stored Cross-Site Scripting (XSS) issue related to syndicated sites within the private area. The output from #URL SYNDIC is not adequately sanitized when displaying details of syndicated sites in the private section. This allows an attacker who can control a malicious syndication URL to inject persistent scripts that will execute when other administrators view the syndicated site details.
Recommendations Update to SPIP version 4.4.9 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27473

Affected Products

Spip