CVE-2022-28959
published 2022-05-19CVE-2022-28959: Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.56%
72.5th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | spip | < spip 3.2.8-1 (bullseye) | spip 3.2.8-1 (bullseye) |
| spip | spip | <= 3.1.13 | — |
| spip | spip | >= 0 < 3.2.8-1 | 3.2.8-1 |
| spip | spip | >= 0 < 3.2.8-1 | 3.2.8-1 |
| spip | spip | >= 0 < 3.2.8-1 | 3.2.8-1 |
| spip | spip | >= 0 < 3.0.21-1ubuntu1+esm1 | 3.0.21-1ubuntu1+esm1 |
| spip | spip | >= 0 < 3.1.4-4~deb9u5ubuntu0.1~esm2 | 3.1.4-4~deb9u5ubuntu0.1~esm2 |
| spip | spip | >= 0 < 3.2.7-1ubuntu0.1+esm2 | 3.2.7-1ubuntu0.1+esm2 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_ubuntu6.2MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
spip vulnerabilities
osv·2026-04-06·CVSS 6.1
CVE-2022-28959 [MEDIUM] spip vulnerabilities
spip vulnerabilities
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform cross site
scripting. (CVE-2022-28959)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform PHP injection
attacks. (CVE-2022-28960)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform SQL injection
attacks. (CVE-2022-28961)
OSV
spip vulnerabilities
osv·2025-03-04·CVSS 6.1
CVE-2022-23638 [MEDIUM] spip vulnerabilities
spip vulnerabilities
It was discovered that svg-sanitizer, vendored in SPIP, did not properly
sanitize SVG/XML content. An attacker could possibly use this issue to
perform cross site scripting. This issue only affected Ubuntu 24.10.
(CVE-2022-23638)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform cross site
scripting. This issue only affected Ubuntu 18.04 LTS. (CVE-2022-28959)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform PHP injection
attacks. This issue only affected Ubuntu 18.04 LTS. (CVE-2022-28960)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to p
GHSA
GHSA-hq48-7c77-c44g: Multiple cross-site scripting (XSS) vulnerabilities in the component /spip
ghsa_unreviewed·2022-05-20
CVE-2022-28959 [MEDIUM] CWE-79 GHSA-hq48-7c77-c44g: Multiple cross-site scripting (XSS) vulnerabilities in the component /spip
Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.
OSV
CVE-2022-28959: Multiple cross-site scripting (XSS) vulnerabilities in the component /spip
osv·2022-05-19·CVSS 6.1
CVE-2022-28959 [MEDIUM] CVE-2022-28959: Multiple cross-site scripting (XSS) vulnerabilities in the component /spip
Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.
Ubuntu
SPIP vulnerabilities
vendor_ubuntu·2026-04-06·CVSS 6.1
CVE-2022-28960 [MEDIUM] SPIP vulnerabilities
Title: SPIP vulnerabilities
Summary: Several security issues were fixed in SPIP.
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform cross site
scripting. (CVE-2022-28959)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform PHP injection
attacks. (CVE-2022-28960)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform SQL injection
attacks. (CVE-2022-28961)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
SPIP vulnerabilities
vendor_ubuntu·2025-03-04·CVSS 6.2
CVE-2022-28959 [MEDIUM] SPIP vulnerabilities
Title: SPIP vulnerabilities
Summary: Several security issues were fixed in spip.
It was discovered that svg-sanitizer, vendored in SPIP, did not properly
sanitize SVG/XML content. An attacker could possibly use this issue to
perform cross site scripting. This issue only affected Ubuntu 24.10.
(CVE-2022-23638)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform cross site
scripting. This issue only affected Ubuntu 18.04 LTS. (CVE-2022-28959)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform PHP injection
attacks. This issue only affected Ubuntu 18.04 LTS. (CVE-2022-28960)
It was discovered that SPIP did not properly sanitize certain
Debian
CVE-2022-28959: spip - Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php o...
vendor_debian·2022·CVSS 6.1
CVE-2022-28959 [MEDIUM] CVE-2022-28959: spip - Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php o...
Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.
Scope: local
bullseye: resolved (fixed in 3.2.8-1)
forky: resolved (fixed in 3.2.8-1)
sid: resolved (fixed in 3.2.8-1)
trixie: resolved (fixed in 3.2.8-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-SPIP-3-2-8-et-SPIP-3-1-13.htmlhttps://github.com/spip/SPIP/commit/0394b44774555ae8331b6e65e35065dfa0bb41e4https://github.com/spip/SPIP/commit/6c1650713fc948318852ace759aab8f1a84791cfhttps://thinkloveshare.com/en/hacking/rce_on_spip_and_root_me/https://www.root-me.org/fr/Informations/Faiblesses-decouvertes/https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-SPIP-3-2-8-et-SPIP-3-1-13.htmlhttps://github.com/spip/SPIP/commit/0394b44774555ae8331b6e65e35065dfa0bb41e4https://github.com/spip/SPIP/commit/6c1650713fc948318852ace759aab8f1a84791cfhttps://thinkloveshare.com/en/hacking/rce_on_spip_and_root_me/https://www.root-me.org/fr/Informations/Faiblesses-decouvertes/
2022-05-19
Published