CVE-2025-71241

MEDIUM

SPIP 4.1.0-4.1.19 - Cross-Site Scripting in Private Area Error Message

Title source: llm
STIX 2.1

Description

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious scripts. This vulnerability is mitigated by the SPIP security screen.

References (3)

Core 3

Scores

CVSS v3 6.1
EPSS 0.0020
EPSS Percentile 10.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
spip/spip 4.1.0 - 4.1.20
Published Feb 19, 2026
Tracked Since Feb 19, 2026