SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security screen.
References
| Link | Resource |
|---|---|
| https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-5.html | Broken Link |
| https://git.spip.net/spip/spip | Product |
| https://www.vulncheck.com/advisories/spip-open-redirect-via-login-form | Third Party Advisory |
Configurations
History
24 Feb 2026, 19:27
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-5.html - Broken Link | |
| References | () https://git.spip.net/spip/spip - Product | |
| References | () https://www.vulncheck.com/advisories/spip-open-redirect-via-login-form - Third Party Advisory | |
| CPE | cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:* | |
| First Time |
Spip spip
Spip |
19 Feb 2026, 16:27
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-19 16:27
Updated : 2026-02-24 19:27
NVD link : CVE-2025-71244
Mitre link : CVE-2025-71244
CVE.ORG link : CVE-2025-71244
JSON object : View
Products Affected
spip
- spip
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
