This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References

No reference.

History

Thu, 19 Feb 2026 15:45:00 +0000

Type Values Removed Values Added
Description SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute malicious scripts. The fix adds a sandbox attribute to iframe tags in the private area. This vulnerability is not mitigated by the SPIP security screen. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Title SPIP < 4.4.8 Cross-Site Scripting via Iframe Tags in Private Area
Weaknesses CWE-79
CPEs cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
Vendors & Products Spip
Spip spip
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Thu, 19 Feb 2026 15:30:00 +0000

Type Values Removed Values Added
Description SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute malicious scripts. The fix adds a sandbox attribute to iframe tags in the private area. This vulnerability is not mitigated by the SPIP security screen.
Title SPIP < 4.4.8 Cross-Site Scripting via Iframe Tags in Private Area
First Time appeared Spip
Spip spip
Weaknesses CWE-79
CPEs cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
Vendors & Products Spip
Spip spip
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: REJECTED

Assigner: VulnCheck

Published:

Updated: 2026-02-19T15:26:13.697Z

Reserved: 2026-02-19T03:00:22.782Z

Link: CVE-2025-71245

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Rejected

Published: 2026-02-19T16:27:12.710

Modified: 2026-02-19T16:27:12.710

Link: CVE-2025-71245

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.