CVE-2023-53900: Spip

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.

Affected products

  • Spip Spip: version 4.1.10 only

Published 2025-12-16. Last modified 2026-06-17.