SPIP Cross-Site Scripting Vulnerability in Code Tags

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in SPIP versions prior to 4.2.15. The issue arises because the application fails to properly sanitize JavaScript embedded within HTML code tags. This oversight enables attackers to inject malicious scripts that can be executed in the context of the victim's browser.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's browser, potentially leading to session hijacking or other malicious actions.

Remediation

Users can update to SPIP version 4.2.15 or later to address this vulnerability. The update can be downloaded from the SPIP official website or via the SPIP loader.

Added: Feb 19, 2026, 6:35 PM
Updated: Feb 19, 2026, 6:35 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
5.8
remediation
7.7
relevance
3.2
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.