CVE-2026-26223
EUVD-2026-758219.02.2026, 16:27
SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute malicious scripts. The fix adds a sandbox attribute to iframe tags in the private area. This vulnerability is not mitigated by the SPIP security screen.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| spip | spip | 4.4.0 ≤ 𝑥 < 4.4.8 |
𝑥
= Vulnerable software versions
Debian Releases