CVE-2026-27474

MEDIUM

SPIP 4.4.0-4.4.8 - Cross-Site Scripting in Private Area via Unsanitized HTML Tags

Title source: llm
STIX 2.1

Description

SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML tags, allowing an attacker to inject malicious scripts through these elements. This vulnerability is not mitigated by the SPIP security screen.

References (3)

Core 3

Scores

CVSS v3 6.1
EPSS 0.0026
EPSS Percentile 17.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
spip/spip 4.4.0 - 4.4.9
Published Feb 19, 2026
Tracked Since Feb 19, 2026