The SPIP jeux plugin versions prior to 4.1.1 contain a...
Moderate severity
Unreviewed
Published
Feb 25, 2026
to the GitHub Advisory Database
•
Updated Feb 25, 2026
Description
Published by the National Vulnerability Database
Feb 25, 2026
Published to the GitHub Advisory Database
Feb 25, 2026
Last updated
Feb 25, 2026
The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_propre pipeline. The plugin incorporates untrusted request parameters into HTML output without proper output encoding, allowing attackers to inject arbitrary script content into pages that render a jeux block. When a victim is induced to visit a crafted URL, the injected content is reflected into the response and executed in the victim's browser context.
References