CVE-2026-27474

SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML tags, allowing an attacker to inject malicious scripts through these elements. This vulnerability is not mitigated by the SPIP security screen.
Configurations

Configuration 1 (hide)

cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

History

02 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 6.1

24 Feb 2026, 19:43

Type Values Removed Values Added
CPE cpe:2.3:a:spip:spip:*:-:*:*:*:*:*:* cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
References () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-9.html - Vendor Advisory, Release Notes () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-9.html - Release Notes, Vendor Advisory

24 Feb 2026, 19:40

Type Values Removed Values Added
CWE CWE-79
CPE cpe:2.3:a:spip:spip:*:-:*:*:*:*:*:*
First Time Spip spip
Spip
References () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-9.html - () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-9.html - Vendor Advisory, Release Notes
References () https://git.spip.net/spip/spip - () https://git.spip.net/spip/spip - Product
References () https://www.vulncheck.com/advisories/spip-cross-site-scripting-in-private-area-incomplete-fix - () https://www.vulncheck.com/advisories/spip-cross-site-scripting-in-private-area-incomplete-fix - Third Party Advisory
Summary
  • (es) SPIP anterior a la versión 4.4.9 permite cross-site scripting (XSS) en el área privada, complementando una corrección incompleta de SPIP 4.4.8. La función echappe_anti_xss() no se aplicó sistemáticamente a las etiquetas HTML input, form, button y anchor (a), permitiendo a un atacante inyectar scripts maliciosos a través de estos elementos. Esta vulnerabilidad no es mitigada por la pantalla de seguridad de SPIP.

19 Feb 2026, 19:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 19:22

Updated : 2026-03-02 15:16


NVD link : CVE-2026-27474

Mitre link : CVE-2026-27474

CVE.ORG link : CVE-2026-27474


JSON object : View

Products Affected

spip

  • spip
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')