Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 20 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML tags, allowing an attacker to inject malicious scripts through these elements. This vulnerability is not mitigated by the SPIP security screen. | |
| Title | SPIP < 4.4.9 Cross-Site Scripting in Private Area (Incomplete Fix) | |
| First Time appeared |
Spip
Spip spip |
|
| CPEs | cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Spip
Spip spip |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-20T20:09:24.292Z
Reserved: 2026-02-19T18:34:45.841Z
Link: CVE-2026-27474
Updated: 2026-02-20T20:09:17.448Z
Status : Awaiting Analysis
Published: 2026-02-19T19:22:30.540
Modified: 2026-02-20T13:49:47.623
Link: CVE-2026-27474
No data.
OpenCVE Enrichment
Updated: 2026-02-20T10:05:56Z
No weakness.