Spip

Spip

85 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 19.02.2026 14:58:19
  • Zuletzt bearbeitet 19.02.2026 19:22:28

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • EPSS -
  • Veröffentlicht 19.02.2026 14:58:18
  • Zuletzt bearbeitet 19.02.2026 19:22:27

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • EPSS -
  • Veröffentlicht 19.02.2026 14:58:17
  • Zuletzt bearbeitet 19.02.2026 16:27:12

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • EPSS -
  • Veröffentlicht 19.02.2026 14:58:16
  • Zuletzt bearbeitet 19.02.2026 16:27:12

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • EPSS 0.18%
  • Veröffentlicht 19.02.2026 14:58:16
  • Zuletzt bearbeitet 24.02.2026 19:27:15

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only aff...

  • EPSS 0.25%
  • Veröffentlicht 19.02.2026 14:58:14
  • Zuletzt bearbeitet 02.03.2026 15:16:31

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, allowing an...

  • EPSS 0.18%
  • Veröffentlicht 19.02.2026 14:58:13
  • Zuletzt bearbeitet 02.03.2026 15:16:31

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious scripts. This vulnera...

  • EPSS 0.17%
  • Veröffentlicht 19.02.2026 14:58:12
  • Zuletzt bearbeitet 24.02.2026 18:53:21

SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a victim's browser.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 16.12.2025 17:06:24
  • Zuletzt bearbeitet 29.04.2026 01:00:01

Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL throu...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 26.11.2024 19:15:31
  • Zuletzt bearbeitet 03.07.2025 00:32:56

A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.