SPIP Cross-Site Scripting Vulnerability in Public Area

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in SPIP versions prior to 4.4.8. This issue arises in the public area under certain edge-case usage patterns, where the 'echapper_html_suspect()' function fails to properly detect all forms of malicious content. As a result, an attacker can inject scripts that execute in the browser of a visitor. Notably, this vulnerability is not addressed by SPIP's security screen.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's browser.

Remediation

Users can update to SPIP version 4.4.8, which includes a fix for this vulnerability. Instructions for updating are available on the SPIP website.

Added: Feb 19, 2026, 6:25 PM
Updated: Feb 19, 2026, 6:25 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
7.2
remediation
7.7
relevance
3.0
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.