Vulnerabilities > Spip > Low

DATE CVE VULNERABILITY TITLE RISK
2022-01-26 CVE-2021-44120 Cross-site Scripting vulnerability in Spip 4.0.0
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields.
network
spip CWE-79
3.5
2022-01-26 CVE-2021-44118 Cross-site Scripting vulnerability in Spip 4.0.0
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability.
network
spip CWE-79
3.5
2005-12-22 CVE-2005-4494 Cross-Site Scripting vulnerability in Spip 1.8.2
Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) spip_login.php3 and (2) spip_pass.php3.
network
high complexity
spip
2.6