0.0
CVE-2025-71248 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
0.0
CVE-2025-71247 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
2.1
CVE-2025-71246 - SPIP < 4.4.8 Cross-Site Scripting in Public Area
SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the public area for certain edge-case usage patterns. The echapper_html_suspect() function does not adequately detect all forms of malicious content, permitting an attacker to inject scripts that execute in a visitor's browser. This vulnerabiliβ¦
4.8
CVE-2025-71245 - SPIP < 4.4.8 Cross-Site Scripting via Iframe Tags in Private Area
SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute malicious scripts. The fix adds a sandbox attribute to iframe tags in β¦
5.1
CVE-2025-71244 - SPIP < 4.4.5 Open Redirect via Login Form
SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overriddβ¦
9.3
CVE-2025-71243 - SPIP Saisies Plugin < 5.11.1 Remote Code Execution
The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to execute arbitrary code on the server. Users should immediately update to version 5.11.1 or later.
5.3
CVE-2025-71242 - SPIP < 4.3.6 Authorization Bypass Leading to Content Disclosure
SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, allowing an authenticated attacker to access restricted contβ¦
4.8
CVE-2025-71241 - SPIP < 4.3.6 Cross-Site Scripting in Private Area
SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious scripts. This vulnerability is mitigated by the SPIP security screen.
4.8
CVE-2025-71240 - SPIP < 4.2.15 Cross-Site Scripting via Code Tags
SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a victim's browser.
8.1
CVE-2026-25755 - jsPDF has PDF Object Injection via Unsanitized Input in addJS Method
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the JavaScript string delimiter, an attacker can execute maliciousβ¦