CVE-2026-27473

SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set a malicious syndication URL to inject persistent scripts that execute when other administrators view the syndicated site details.
Configurations

Configuration 1 (hide)

cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

History

24 Feb 2026, 19:44

Type Values Removed Values Added
CWE CWE-79
First Time Spip spip
Spip
CPE cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
Summary
  • (es) SPIP anterior a 4.4.9 permite Cross-Site Scripting Almacenado (XSS) a través de sitios sindicados en el área privada. La salida #URL_SYNDIC no se sanea correctamente en la página privada del sitio sindicado, permitiendo a un atacante que puede establecer una URL de sindicación maliciosa inyectar scripts persistentes que se ejecutan cuando otros administradores ven los detalles del sitio sindicado.
References () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-9.html - () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-9.html - Vendor Advisory, Release Notes
References () https://git.spip.net/spip/spip - () https://git.spip.net/spip/spip - Product
References () https://www.vulncheck.com/advisories/spip-stored-cross-site-scripting-via-syndicated-sites - () https://www.vulncheck.com/advisories/spip-stored-cross-site-scripting-via-syndicated-sites - Third Party Advisory

19 Feb 2026, 19:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 19:22

Updated : 2026-02-24 19:44


NVD link : CVE-2026-27473

Mitre link : CVE-2026-27473

CVE.ORG link : CVE-2026-27473


JSON object : View

Products Affected

spip

  • spip
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')