Search CVE reports
11 – 20 of 46 results
CVE-2022-26847
Medium prioritySome fixes available 2 of 5
SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.
1 affected packages
spip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
spip | Not affected | Vulnerable | Vulnerable | Fixed | Not affected |
CVE-2022-26846
Medium prioritySome fixes available 2 of 5
SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.
1 affected packages
spip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
spip | Not affected | Vulnerable | Vulnerable | Fixed | Not affected |
CVE-2022-23638
Medium prioritysvg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no...
1 affected packages
spip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
spip | Vulnerable | Vulnerable | Not affected | Not affected | Not affected |
CVE-2021-44123
Medium prioritySome fixes available 3 of 4
SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.
1 affected packages
spip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
spip | Not affected | Not affected | Fixed | Fixed | Vulnerable |
CVE-2021-44122
Medium prioritySome fixes available 3 of 4
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious...
1 affected packages
spip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
spip | Not affected | Not affected | Fixed | Fixed | Vulnerable |
CVE-2021-44120
Medium prioritySome fixes available 3 of 4
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has...
1 affected packages
spip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
spip | Not affected | Not affected | Fixed | Fixed | Vulnerable |
CVE-2021-44118
Medium prioritySome fixes available 3 of 4
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running...
1 affected packages
spip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
spip | Not affected | Not affected | Fixed | Fixed | Vulnerable |
CVE-2020-28984
Medium prioritySome fixes available 1 of 4
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
1 affected packages
spip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
spip | Not affected | Not affected | Needs evaluation | Fixed | Needs evaluation |
CVE-2019-19830
Medium prioritySome fixes available 1 of 3
_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.
1 affected packages
spip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
spip | — | — | Not affected | Fixed | Not affected |
CVE-2019-16394
Medium prioritySome fixes available 1 of 4
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.
1 affected packages
spip
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
spip | Not affected | Not affected | Not affected | Fixed | Vulnerable |