CVE-2026-27473

Vulnerability

CVE-2026-27473

CVE-2026-27473

 

SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set a malicious syndication URL to inject persistent scripts that execute when other administrators view the syndicated site details.

References
severitym
medium

type: vendor

source: launchpad.net/ubuntu-cve-tracker

published: 2026-02-20 00:00:00

Detection

No detection criteria available for this vulnerability.

Data Sources

  • Ubuntu CVE Tracker

    ubuntu-cve-tracker

VulsFutureVuls|GitHub Logo IconGitHub