CVE-2026-26345
Received Received - Intake
Cross-Site Scripting in SPIP Public Area Before

Publication date: 2026-02-19

Last updated on: 2026-02-24

Assigner: VulnCheck

Description
SPIP before 4.4.8 contains a stored cross-site scripting (XSS) vulnerability in the public area triggered in certain edge-case usage patterns. The echapper_html_suspect() function does not adequately sanitize user-controlled content, allowing authenticated users with content-editing privileges (e.g., author-level roles and above) to inject malicious scripts. The injected payload may be rendered across multiple pages within the framework and execute in the browser context of other users, including administrators. Successful exploitation can allow attackers to perform actions in the security context of the victim user, including unauthorized modification of application state. This vulnerability is not mitigated by the SPIP security screen.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-19
Last Modified
2026-02-24
Generated
2026-06-16
AI Q&A
2026-02-19
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
spip spip From 4.4.0 (inc) to 4.4.8 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in SPIP versions before 4.4.8 and allows Cross-Site Scripting (XSS) attacks in the public area under certain edge-case usage patterns.

The issue arises because the function echapper_html_suspect() does not properly detect all forms of malicious content, enabling an attacker to inject scripts that execute in a visitor's browser.

Additionally, this vulnerability is not mitigated by the SPIP security screen.

Impact Analysis

An attacker exploiting this vulnerability can inject malicious scripts that run in the browsers of visitors to the affected SPIP site.

This can lead to unauthorized actions such as stealing session cookies, redirecting users to malicious sites, or performing actions on behalf of the user without their consent.

The impact is limited by the relatively low CVSS scores, indicating that exploitation requires user interaction and has limited scope and impact.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-26345. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart