Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
spip spip vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2021-44120
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes ...
Spip Spip 4.0.0
5.3
CVSSv3
CVE-2022-26847
SPIP prior to 3.2.14 and 4.x prior to 4.0.5 allows unauthenticated access to information about editorial objects.
Spip Spip
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Debian Debian Linux 11.0
5.3
CVSSv3
CVE-2019-16394
SPIP prior to 3.1.11 and 3.2 prior to 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help malicious users to enumerate subscribers.
Spip Spip
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Canonical Ubuntu Linux 18.04
NA
CVE-2013-7303
Multiple cross-site scripting (XSS) vulnerabilities in (1) squelettes-dist/formulaires/inscription.php and (2) prive/forms/editer_auteur.php in SPIP prior to 2.1.25 and 3.0.x prior to 3.0.13 allow remote malicious users to inject arbitrary web script or HTML via the author name f...
Spip Spip 3.0.3
Spip Spip 3.0.4
Spip Spip 2.1.23
Spip Spip 2.1.22
Spip Spip 2.1.16
Spip Spip 2.1.15
Spip Spip 2.0.9
Spip Spip 2.0.8
Spip Spip 2.0.21
Spip Spip 2.0.20
Spip Spip 2.0.14
Spip Spip 2.0.13
Spip Spip 3.0.10
Spip Spip 3.0.11
Spip Spip 3.0.2
Spip Spip 3.0.9
Spip Spip
Spip Spip 2.1.18
Spip Spip 2.1.17
Spip Spip 2.1.1
Spip Spip 2.1
Spip Spip 2.0.3
NA
CVE-2013-4555
Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in SPIP prior to 2.1.24 allows remote malicious users to hijack the authentication of arbitrary users for requests that logout the user via unspecified vectors.
Spip Spip 2.1.16
Spip Spip 2.1.15
Spip Spip 2.0.9
Spip Spip 2.0.8
Spip Spip 2.0.20
Spip Spip 2.0.2
Spip Spip 2.0.13
Spip Spip 2.0.12
Spip Spip 2.1.8
Spip Spip 2.1.7
Spip Spip 2.1.2
Spip Spip 2.1.19
Spip Spip 2.1.12
Spip Spip 2.1.11
Spip Spip 2.0.5
Spip Spip 2.0.4
Spip Spip 2.0.17
Spip Spip 2.0.16
Spip Spip 2.0.1
Spip Spip 2.0.0
Spip Spip 2.1.5
Spip Spip 2.1.22
NA
CVE-2013-4556
Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP prior to 2.1.24 and 3.0.x prior to 3.0.12 allows remote malicious users to inject arbitrary web script or HTML via the url_site parameter.
Spip Spip 3.0.3
Spip Spip 3.0.4
Spip Spip 2.1.21
Spip Spip 2.1.20
Spip Spip 2.1.14
Spip Spip 2.1.13
Spip Spip 2.0.7
Spip Spip 2.0.6
Spip Spip 2.0.19
Spip Spip 2.0.18
Spip Spip 2.0.11
Spip Spip 3.0.0
Spip Spip 3.0.7
Spip Spip 3.0.8
Spip Spip 2.1.18
Spip Spip 2.1.17
Spip Spip 2.1.10
Spip Spip 2.1.1
Spip Spip 2.0.3
Spip Spip 2.0.22
Spip Spip 2.0.15
Spip Spip 2.0.14
NA
CVE-2013-4557
The Security Screen (_core_/securite/ecran_securite.php) prior to 1.1.8 for SPIP, as used in SPIP 3.0.x prior to 3.0.12, allows remote malicious users to execute arbitrary PHP via the connect parameter.
Spip Spip 3.0.0
Spip Spip 3.0.1
Spip Spip 3.0.8
Spip Spip 3.0.9
Spip Spip 3.0.4
Spip Spip 3.0.5
Spip Spip 3.0.2
Spip Spip 3.0.3
Spip Spip 3.0.10
Spip Spip 3.0.11
Spip Spip 3.0.6
Spip Spip 3.0.7
NA
CVE-2013-2118
SPIP 3.0.x prior to 3.0.9, 2.1.x prior to 2.1.22, and 2.0.x prior to 2.0.23 allows remote malicious users to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.
Spip Spip 3.0.1
Spip Spip 3.0.2
Spip Spip 3.0.3
Spip Spip 3.0.4
Spip Spip 3.0.0
Spip Spip 3.0.5
Spip Spip 3.0.7
Spip Spip 3.0.6
Spip Spip 3.0.8
Spip Spip 2.1.1
Spip Spip 2.1.2
Spip Spip 2.1.3
Spip Spip 2.1.17
Spip Spip 2.1.18
Spip Spip 2.1.19
Spip Spip 2.1.20
Spip Spip 2.1.9
Spip Spip 2.1.10
Spip Spip 2.1.11
Spip Spip 2.1.12
Spip Spip 2.1.5
Spip Spip 2.1.7
1 EDB exploit
NA
CVE-2012-4331
Multiple unspecified vulnerabilities in SPIP prior to 1.9.2.o, 2.0.x prior to 2.0.18, and 2.1.x prior to 2.1.13 have unknown impact and attack vectors that are not related to cross-site scripting (XSS), different vulnerabilities than CVE-2012-2151.
Spip Spip 1.9
Spip Spip 1.9.1
Spip Spip 1.9.2
Spip Spip 2.0
Spip Spip 2.1
NA
CVE-2012-2151
Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x prior to 1.9.2.o, 2.0.x prior to 2.0.18, and 2.1.x prior to 2.1.13 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Spip Spip 1.9
Spip Spip 1.9.1
Spip Spip 1.9.2
Spip Spip 2.0
Spip Spip 2.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »