Search CVE reports


Toggle filters

11 – 20 of 48 results


CVE-2022-28960

High priority
Needs evaluation

A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-28959

Medium priority
Needs evaluation

Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-26847

Medium priority

Some fixes available 2 of 5

SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Vulnerable Vulnerable Fixed Not affected
Show less packages

CVE-2022-26846

Medium priority

Some fixes available 2 of 5

SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Vulnerable Vulnerable Fixed Not affected
Show less packages

CVE-2022-23638

Medium priority
Vulnerable

svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Vulnerable Vulnerable Not affected Not affected Not affected
Show less packages

CVE-2021-44123

Medium priority

Some fixes available 3 of 4

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2021-44122

Medium priority

Some fixes available 3 of 4

SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2021-44120

Medium priority

Some fixes available 3 of 4

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2021-44118

Medium priority

Some fixes available 3 of 4

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2020-28984

Medium priority

Some fixes available 1 of 4

prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Needs evaluation Fixed Needs evaluation
Show less packages