Debian Spip vulnerabilities
67 known vulnerabilities affecting debian/spip.
Total CVEs
67
CISA KEV
0
Public exploits
14
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH19MEDIUM36LOW4
Vulnerabilities
Page 4 of 4
CVE-2016-9997P4MEDIUMCVSS 6.1fixed in spip 3.1.4-2 (bullseye)2016
CVE-2016-9997 [MEDIUM] CVE-2016-9997: spip - SPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in /ecrir...
SPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/puce_statut.php involving the `$id` parameter, as demonstrated by a /ecrire/?exec=puce_statut URL.
Scope: local
bullseye: resolved (fixed in 3.1.4-2)
forky: resolved (fixed in 3.1.4-2)
sid: resolved (fixed in 3.1.4-2)
trixie: resolved (fixed in 3.1.4-2)
debian
CVE-2012-2151P4LOWCVSS 4.3fixed in spip 2.1.13-1 (bullseye)2012
CVE-2012-2151 [MEDIUM] CVE-2012-2151: spip - Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x before 1.9.2.o...
Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Scope: local
bullseye: resolved (fixed in 2.1.13-1)
forky: resolved (fixed in 2.1.13-1)
sid: resolved (fixed in 2.1.13-1)
trixie: resolved (fixed in 2.1.13-1
debian
CVE-2013-7303P4MEDIUMCVSS 4.3fixed in spip 3.0.13-1 (bullseye)2013
CVE-2013-7303 [MEDIUM] CVE-2013-7303: spip - Multiple cross-site scripting (XSS) vulnerabilities in (1) squelettes-dist/formu...
Multiple cross-site scripting (XSS) vulnerabilities in (1) squelettes-dist/formulaires/inscription.php and (2) prive/forms/editer_auteur.php in SPIP before 2.1.25 and 3.0.x before 3.0.13 allow remote attackers to inject arbitrary web script or HTML via the author name field.
Scope: local
bullseye: resolved (fixed in 3.0.13-1)
forky: resolved (fixed in 3.0.13-1)
sid: re
debian
CVE-2013-4556P4MEDIUMCVSS 4.3fixed in spip 2.1.24-1 (bullseye)2013
CVE-2013-4556 [MEDIUM] CVE-2013-4556: spip - Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/e...
Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter.
Scope: local
bullseye: resolved (fixed in 2.1.24-1)
forky: resolved (fixed in 2.1.24-1)
sid: resolved (fixed in 2.1.24-1)
trixie: resolv
debian
CVE-2006-1295P4MEDIUMCVSS 4.3fixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-1295 [MEDIUM] CVE-2006-1295: spip - Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allow...
Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.
Scope: local
bullseye: resolved (fixed in 2.0.6-1)
forky: resolved (fixed in 2.0.6-1)
sid: resolved (fixed in 2.0.6-1)
trixie: resolved (fixed in 2.0.6-1)
debian
CVE-2005-4494P4MEDIUMCVSS 2.6fixed in spip 2.0.6-1 (bullseye)2005
CVE-2005-4494 [LOW] CVE-2005-4494: spip - Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier allows remote...
Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) spip_login.php3 and (2) spip_pass.php3.
Scope: local
bullseye: resolved (fixed in 2.0.6-1)
forky: resolved (fixed in 2.0.6-1)
sid: resolved (fixed in 2.0.6-1)
trixie: resolved (fixed in 2.0.6-1)
debian
CVE-2006-0519P4MEDIUMCVSS 5.0fixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-0519 [MEDIUM] CVE-2006-0519: spip - SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attack...
SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to obtain sensitive information via a direct request to inc-messforum.php3, which reveals the path in an error message.
Scope: local
bullseye: resolved (fixed in 2.0.6-1)
forky: resolved (fixed in 2.0.6-1)
sid: resolved (fixed in 2.0.6-1)
trixie: resolved (fixed in 2.0.6-1)
debian
← Previous4 / 4