PT-2026-42973 · Spip · Spip

Germain Ngoyi

+1

·

Published

2026-05-24

·

Updated

2026-05-25

·

CVE-2026-48832

CVSS v3.1

3.5

Low

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SPIP versions prior to 4.4.15
Description The 'action/cookie.php' endpoint in the 'ecrire' component is subject to an open redirect, which occurs when an application redirects users to an external site without sufficient validation of the destination URL.
Recommendations Update to version 4.4.15 or later.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2026-48832

Affected Products

Spip