CVE-2016-7981
- EPSS 52.22%
- Published 18.01.2017 17:59:00
- Last modified 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.
CVE-2016-7980
- EPSS 0.55%
- Published 18.01.2017 17:59:00
- Last modified 20.04.2025 01:37:25
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted ...
CVE-2016-9998
- EPSS 0.29%
- Published 17.12.2016 03:59:00
- Last modified 12.04.2025 10:46:40
SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/info_plugin.php involving the `$plugin` parameter, as demonstrated by a /ecrire/?exec=info_plugin URL.
CVE-2016-9997
- EPSS 0.29%
- Published 17.12.2016 03:59:00
- Last modified 12.04.2025 10:46:40
SPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/puce_statut.php involving the `$id` parameter, as demonstrated by a /ecrire/?exec=puce_statut URL.
CVE-2016-9152
- EPSS 0.25%
- Published 05.12.2016 18:59:01
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in ecrire/exec/plonger.php in SPIP 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the rac parameter.
CVE-2016-3154
- EPSS 1.46%
- Published 08.04.2016 14:59:04
- Last modified 12.04.2025 10:46:40
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialize...
CVE-2016-3153
- EPSS 1.46%
- Published 08.04.2016 14:59:03
- Last modified 12.04.2025 10:46:40
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrer_entites function.
CVE-2013-7303
- EPSS 0.43%
- Published 30.01.2014 21:55:04
- Last modified 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in (1) squelettes-dist/formulaires/inscription.php and (2) prive/forms/editer_auteur.php in SPIP before 2.1.25 and 3.0.x before 3.0.13 allow remote attackers to inject arbitrary web script or HTML v...
CVE-2013-4557
- EPSS 69.49%
- Published 18.11.2013 02:55:08
- Last modified 11.04.2025 00:51:21
The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execute arbitrary PHP via the connect parameter.
CVE-2013-4556
- EPSS 0.33%
- Published 18.11.2013 02:55:08
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter.