CVE-2026-48832: Spip

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.

Affected products

  • Spip Spip: before 4.4.15 (fixed in 4.4.15)

Published 2026-05-24. Last modified 2026-07-23.