Spip

Spip

85 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.59%
  • Veröffentlicht 19.05.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:58:14

Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.

  • EPSS 1.36%
  • Veröffentlicht 10.03.2022 17:48:02
  • Zuletzt bearbeitet 21.11.2024 06:54:38

SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.

  • EPSS 3.06%
  • Veröffentlicht 10.03.2022 17:48:01
  • Zuletzt bearbeitet 21.11.2024 06:54:38

SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.

  • EPSS 2.4%
  • Veröffentlicht 26.01.2022 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:24

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

  • EPSS 0.49%
  • Veröffentlicht 26.01.2022 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:24

SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirec...

  • EPSS 0.63%
  • Veröffentlicht 26.01.2022 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:23

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written an...

  • EPSS 0.77%
  • Veröffentlicht 26.01.2022 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:23

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side ...

  • EPSS 2.19%
  • Veröffentlicht 23.11.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 05:23:26

prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.

  • EPSS 1.27%
  • Veröffentlicht 17.12.2019 05:15:14
  • Zuletzt bearbeitet 21.11.2024 04:35:28

_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.

  • EPSS 1.49%
  • Veröffentlicht 17.09.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:30:37

SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.