CVE-2026-27474

EUVD-2026-8320
SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML tags, allowing an attacker to inject malicious scripts through these elements. This vulnerability is not mitigated by the SPIP security screen.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
spipspip
4.4.0 ≤
𝑥
< 4.4.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
spip
bullseye
vulnerable
bullseye (security)
vulnerable
forky
4.4.13+dfsg-1
fixed
sid
4.4.13+dfsg-1
fixed
trixie
4.4.11+dfsg-0+deb13u1
fixed
trixie (security)
4.4.13+dfsg-0+deb13u1
fixed