SPIP Cross-Site Scripting Vulnerability via Iframe Tags in Private Area

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in SPIP versions prior to 4.4.8. This issue arises in the private area, where the application fails to properly sandbox or escape iframe content, allowing attackers to inject and execute malicious scripts. The vulnerability is not mitigated by the SPIP security screen.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Remediation

Users can update to SPIP version 4.4.8, which addresses this vulnerability by adding a sandbox attribute to iframe tags in the private area. For those using external video services like PeerTube, YouTube, or Dailymotion, it is recommended to install the latest version of the oEmbed plugin.

Added: Feb 19, 2026, 6:27 PM
Updated: Feb 19, 2026, 6:27 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
5.8
remediation
7.7
relevance
3.2
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.