SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious scripts. This vulnerability is mitigated by the SPIP security screen.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious scripts. This vulnerability is mitigated by the SPIP security screen. | |
| Title | SPIP < 4.3.6 Cross-Site Scripting in Private Area | |
| First Time appeared |
Spip
Spip spip |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Spip
Spip spip |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-19T14:58:13.755Z
Updated: 2026-02-19T14:58:13.755Z
Reserved: 2026-02-19T03:00:22.781Z
Link: CVE-2025-71241
No data.
Status : Received
Published: 2026-02-19T16:27:11.903
Modified: 2026-02-19T16:27:11.903
Link: CVE-2025-71241
No data.