CVE-2013-7303

SPIP <3.0.13 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in (1) squelettes-dist/formulaires/inscription.php and (2) prive/forms/editer_auteur.php in SPIP before 2.1.25 and 3.0.x before 3.0.13 allow remote attackers to inject arbitrary web script or HTML via the author name field.

Scores

EPSS 0.0043
EPSS Percentile 62.0%

Details

CWE
CWE-79
Status published
Products (50)
spip/spip < 2.1.24
spip/spip
spip/spip
spip/spip
spip/spip
spip/spip
spip/spip
spip/spip
spip/spip
spip/spip
... and 40 more
Published Jan 30, 2014
Tracked Since Feb 18, 2026