CVE-2023-53900: Spip
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.
Affected products
- Spip Spip: version 4.1.10 only
Published 2025-12-16. Last modified 2026-06-17.