Debian Spip vulnerabilities
67 known vulnerabilities affecting debian/spip.
Total CVEs
67
CISA KEV
0
Public exploits
14
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH19MEDIUM36LOW4
Vulnerabilities
Page 3 of 4
CVE-2022-26847P4MEDIUMCVSS 5.3fixed in spip 3.2.11-3+deb11u3 (bullseye)2022
CVE-2022-26847 [MEDIUM] CVE-2022-26847: spip - SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to informa...
SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.
Scope: local
bullseye: resolved (fixed in 3.2.11-3+deb11u3)
forky: resolved (fixed in 4.0.5-1)
sid: resolved (fixed in 4.0.5-1)
trixie: resolved (fixed in 4.0.5-1)
debian
CVE-2012-4331P4MEDIUMCVSS 4.3fixed in spip 2.1.13-1 (bullseye)2012
CVE-2012-4331 [MEDIUM] CVE-2012-4331: spip - Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18...
Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vectors that are not related to cross-site scripting (XSS), different vulnerabilities than CVE-2012-2151.
Scope: local
bullseye: resolved (fixed in 2.1.13-1)
forky: resolved (fixed in 2.1.13-1)
sid: resolved (fixed in 2.1.13-1)
trixie
debian
CVE-2013-4555P4MEDIUMCVSS 6.8fixed in spip 2.1.24-1 (bullseye)2013
CVE-2013-4555 [MEDIUM] CVE-2013-4555: spip - Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in S...
Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in SPIP before 2.1.24 allows remote attackers to hijack the authentication of arbitrary users for requests that logout the user via unspecified vectors.
Scope: local
bullseye: resolved (fixed in 2.1.24-1)
forky: resolved (fixed in 2.1.24-1)
sid: resolved (fixed in 2.1.24-1)
trixie: resolved (fi
debian
CVE-2026-26345P4HIGHCVSS 8.6fixed in spip 4.4.9+dfsg-1 (forky)2026
CVE-2026-26345 [HIGH] CVE-2026-26345: spip - SPIP before 4.4.8 contains a stored cross-site scripting (XSS) vulnerability in ...
SPIP before 4.4.8 contains a stored cross-site scripting (XSS) vulnerability in the public area triggered in certain edge-case usage patterns. The echapper_html_suspect() function does not adequately sanitize user-controlled content, allowing authenticated users with content-editing privileges (e.g., author-level roles and above) to inject malicious scripts. The inject
debian
CVE-2026-27472P4MEDIUMCVSS 5.3fixed in spip 4.4.9+dfsg-1 (forky)2026
CVE-2026-27472 [MEDIUM] CVE-2026-27472: spip - SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated...
SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is a valid remote URL, allowing an authenticated attacker to make the server issue requests to arbitrary internal or external destinations. This vulnerability is not mitiga
debian
CVE-2025-71244P4MEDIUMCVSS 5.1fixed in spip 4.4.5+dfsg-1 (forky)2025
CVE-2025-71244 [MEDIUM] CVE-2025-71244: spip - SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used...
SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security
debian
CVE-2026-27474P4MEDIUMCVSS 4.8fixed in spip 4.4.9+dfsg-1 (forky)2026
CVE-2026-27474 [MEDIUM] CVE-2026-27474: spip - SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complem...
SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML tags, allowing an attacker to inject malicious scripts through these elements. This vulnerability is not mitigated by the SPIP security scre
debian
CVE-2023-52322P4MEDIUMCVSS 6.1fixed in spip 3.2.11-3+deb11u10 (bullseye)2023
CVE-2023-52322 [MEDIUM] CVE-2023-52322: spip - ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows ...
ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.
Scope: local
bullseye: resolved (fixed in 3.2.11-3+deb11u10)
forky: resolved (fixed in 4.1.13+dfsg-1)
sid: resolved (fixed in 4.1.13+dfsg-1)
trixie: resolved (fixed in 4.1.13+dfsg-1)
debian
CVE-2026-26223P4MEDIUMCVSS 5.1fixed in spip 4.4.9+dfsg-1 (forky)2026
CVE-2026-26223 [MEDIUM] CVE-2026-26223: spip - SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via mali...
SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute malicious scripts. The fix adds a sandbox attribute to iframe tags in the private area. This vulnerability is not mitigated by the SPIP secu
debian
CVE-2025-71241P4MEDIUMCVSS 4.8fixed in spip 4.3.6+dfsg-1 (forky)2025
CVE-2025-71241 [MEDIUM] CVE-2025-71241: spip - SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the p...
SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious scripts. This vulnerability is mitigated by the SPIP security screen.
Scope: local
bullseye: open
forky: resolved (fixed in 4.3.6+dfsg-1)
si
debian
CVE-2022-28959P4MEDIUMCVSS 6.1fixed in spip 3.2.8-1 (bullseye)2022
CVE-2022-28959 [MEDIUM] CVE-2022-28959: spip - Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php o...
Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.
Scope: local
bullseye: resolved (fixed in 3.2.8-1)
forky: resolved (fixed in 3.2.8-1)
sid: resolved (fixed in 3.2.8-1)
trixie: resolved (fixed in 3.2.8-1)
debian
CVE-2021-44118P4MEDIUMCVSS 5.4fixed in spip 3.2.11-3+deb11u1 (bullseye)2021
CVE-2021-44118 [MEDIUM] CVE-2021-44118: spip - SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit...
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).
Scope: local
bullseye: resolved (fixed in 3.2.11-3+deb11u1)
forky:
debian
CVE-2021-44120P4MEDIUMCVSS 5.4fixed in spip 3.2.11-3+deb11u1 (bullseye)2021
CVE-2021-44120 [MEDIUM] CVE-2021-44120: spip - SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/p...
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes to the public site and wants to read the author's information, the malicious code will be
debian
CVE-2019-16392P4MEDIUMCVSS 6.1fixed in spip 3.2.5-1 (bullseye)2019
CVE-2019-16392 [MEDIUM] CVE-2019-16392: spip - SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS v...
SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
Scope: local
bullseye: resolved (fixed in 3.2.5-1)
forky: resolved (fixed in 3.2.5-1)
sid: resolved (fixed in 3.2.5-1)
trixie: resolved (fixed in 3.2.5-1)
debian
CVE-2019-16393P4MEDIUMCVSS 6.1fixed in spip 3.2.5-1 (bullseye)2019
CVE-2019-16393 [MEDIUM] CVE-2019-16393: spip - SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/h...
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
Scope: local
bullseye: resolved (fixed in 3.2.5-1)
forky: resolved (fixed in 3.2.5-1)
sid: resolved (fixed in 3.2.5-1)
trixie: resolved (fixed in 3.2.5-1)
debian
CVE-2024-23659P4LOWCVSS 6.1fixed in spip 4.1.15+dfsg-1 (forky)2024
CVE-2024-23659 [MEDIUM] CVE-2024-23659: spip - SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded...
SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.
Scope: local
bullseye: resolved
forky: resolved (fixed in 4.1.15+dfsg-1)
sid: resolved (fixed in 4.1.15+dfsg-1)
trixie: resolved (fixed in 4.1.15+dfsg-1)
debian
CVE-2025-71240P4MEDIUMCVSS 4.8fixed in spip 4.3.0+dfsg-1 (forky)2025
CVE-2025-71240 [MEDIUM] CVE-2025-71240: spip - SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML...
SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a victim's browser.
Scope: local
bullseye: open
forky: resolved (fixed in 4.3.0+dfsg-1)
sid: resolved (fixed in 4.3.0+dfsg-1)
trixie: resolved
debian
CVE-2017-15736P4MEDIUMCVSS 6.1fixed in spip 3.1.4-4 (bullseye)2017
CVE-2017-15736 [MEDIUM] CVE-2017-15736: spip - Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows re...
Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web script or HTML via a crafted string, as demonstrated by a PGP field, related to prive/objets/contenu/auteur.html and ecrire/inc/texte_mini.php.
Scope: local
bullseye: resolved (fixed in 3.1.4-4)
forky: resolved (fixed in 3.1.4-4)
sid: resolved (fixed
debian
CVE-2016-9152P4MEDIUMCVSS 6.1fixed in spip 3.1.4-2 (bullseye)2016
CVE-2016-9152 [MEDIUM] CVE-2016-9152: spip - Cross-site scripting (XSS) vulnerability in ecrire/exec/plonger.php in SPIP 3.1....
Cross-site scripting (XSS) vulnerability in ecrire/exec/plonger.php in SPIP 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the rac parameter.
Scope: local
bullseye: resolved (fixed in 3.1.4-2)
forky: resolved (fixed in 3.1.4-2)
sid: resolved (fixed in 3.1.4-2)
trixie: resolved (fixed in 3.1.4-2)
debian
CVE-2016-9998P4MEDIUMCVSS 6.1fixed in spip 3.1.4-2 (bullseye)2016
CVE-2016-9998 [MEDIUM] CVE-2016-9998: spip - SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire...
SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/info_plugin.php involving the `$plugin` parameter, as demonstrated by a /ecrire/?exec=info_plugin URL.
Scope: local
bullseye: resolved (fixed in 3.1.4-2)
forky: resolved (fixed in 3.1.4-2)
sid: resolved (fixed in 3.1.4-2)
trixie: resolved (fixed in 3.1.4-2)
debian