CVE-2026-26223: Spip

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute malicious scripts. The fix adds a sandbox attribute to iframe tags in the private area. This vulnerability is not mitigated by the SPIP security screen.

Affected products

  • Spip Spip: from 4.4.0, before 4.4.8 (fixed in 4.4.8)

Published 2026-02-19. Last modified 2026-06-17.