SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in...
Low severity
Unreviewed
Published
Feb 19, 2026
to the GitHub Advisory Database
•
Updated Feb 24, 2026
Description
Published by the National Vulnerability Database
Feb 19, 2026
Published to the GitHub Advisory Database
Feb 19, 2026
Last updated
Feb 24, 2026
SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the public area for certain edge-case usage patterns. The echapper_html_suspect() function does not adequately detect all forms of malicious content, permitting an attacker to inject scripts that execute in a visitor's browser. This vulnerability is not mitigated by the SPIP security screen.
References