CVE-2026-26223: Spip
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute malicious scripts. The fix adds a sandbox attribute to iframe tags in the private area. This vulnerability is not mitigated by the SPIP security screen.
Affected products
- Spip Spip: from 4.4.0, before 4.4.8 (fixed in 4.4.8)
Published 2026-02-19. Last modified 2026-06-17.